https://malware-filter.gitlab.io/malware-filter/urlhaus-filter-snort2-online.rules Open raw list Description
Filter list covering malware. Maintained by Ming Di Leom. See the project homepage for details and inclusion criteria.
Integration
No specific instructions available. Add the list URL to your blocker:
https://malware-filter.gitlab.io/malware-filter/urlhaus-filter-snort2-online.rules Recent changes
Recently added entries
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.53.15.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000021; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.68.74.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000022; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.101.85.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000023; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.101.85.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000024; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.106.250.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000025; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.116.190.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000026; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.125.163.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000027; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.154.90.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000028; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.159.152.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000029; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.159.221.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000030; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.128.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000033; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.18.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000034; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.200.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000035; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.168.67.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000036; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.179.240.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000037; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.187.151.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000038; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.20.213.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000039; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.203.210.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000040; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.226.249.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000045; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.227.118.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000046; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.231.14.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000047; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.240.211.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000048; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.245.10.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000049; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.245.204.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000050; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.247.164.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000051; rev:1;)
Recently removed entries
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.53.15.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000021; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.53.15.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000022; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.68.74.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000023; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.101.85.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000024; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.101.85.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000025; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.106.250.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000026; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.116.190.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000027; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.125.163.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000028; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.153.93.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000029; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.154.90.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000030; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.117.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000033; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.128.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000034; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.18.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000035; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.200.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000036; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.168.67.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000037; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.179.240.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000038; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.187.151.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000039; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.20.213.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000040; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.227.118.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000045; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.231.14.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000046; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.236.133.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100000047; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.236.135.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000048; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.240.211.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000049; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.245.10.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000050; rev:1;)
- alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.245.204.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000051; rev:1;)
