urlhaus-filter (Snort 2)

von Ming Di Leom Malware Regex
https://malware-filter.gitlab.io/malware-filter/urlhaus-filter-snort2-online.rules Rohliste öffnen
9.448Einträge
+9.422 -9.489letzte Änderung
zuletzt aktualisiert
3,2 MBGröße
vor 3 Stundenzuletzt geprüft

Beschreibung

Filterliste aus den Bereichen Malware. Betreut von Ming Di Leom. Einzelheiten und Aufnahmekriterien stehen auf der Projektseite.

Integration

Keine spezifische Anleitung verfügbar. Fügen Sie die Listen-URL in Ihrem Blocker hinzu:

https://malware-filter.gitlab.io/malware-filter/urlhaus-filter-snort2-online.rules

Letzte Änderungen

Kürzlich hinzugefügte Einträge

  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.53.15.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000021; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.68.74.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000022; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.101.85.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000023; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.101.85.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000024; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.106.250.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000025; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.116.190.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000026; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.125.163.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000027; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.154.90.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000028; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.159.152.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000029; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.159.221.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000030; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.128.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000033; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.18.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000034; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.200.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000035; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.168.67.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000036; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.179.240.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000037; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.187.151.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000038; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.20.213.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000039; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.203.210.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000040; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.226.249.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000045; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.227.118.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000046; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.231.14.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000047; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.240.211.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000048; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.245.10.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000049; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.245.204.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000050; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.247.164.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000051; rev:1;)

Kürzlich entfernte Einträge

  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.53.15.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000021; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.53.15.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000022; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.68.74.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000023; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.101.85.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000024; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.101.85.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000025; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.106.250.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000026; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.116.190.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000027; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.125.163.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000028; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.153.93.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000029; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.154.90.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000030; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.117.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000033; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.128.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000034; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.18.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000035; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.200.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000036; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.168.67.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000037; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.179.240.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000038; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.187.151.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000039; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.20.213.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000040; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.227.118.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000045; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.231.14.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000046; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.236.133.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100000047; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.236.135.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000048; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.240.211.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000049; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.245.10.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000050; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.245.204.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000051; rev:1;)
Nach oben scrollen