urlhaus-filter (Snort 2)

by Ming Di Leom Malware
https://malware-filter.gitlab.io/malware-filter/urlhaus-filter-snort2-online.rules Open raw list
9,448entries
+9,422 -9,489last change
last updated
3.2 MBsize
6 hours agolast checked

Description

Filter list covering malware. Maintained by Ming Di Leom. See the project homepage for details and inclusion criteria.

Integration

No specific instructions available. Add the list URL to your blocker:

https://malware-filter.gitlab.io/malware-filter/urlhaus-filter-snort2-online.rules

Recent changes

Recently added entries

  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.53.15.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000021; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.68.74.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000022; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.101.85.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000023; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.101.85.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000024; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.106.250.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000025; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.116.190.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000026; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.125.163.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000027; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.154.90.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000028; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.159.152.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000029; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.159.221.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000030; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.128.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000033; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.18.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000034; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.200.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000035; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.168.67.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000036; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.179.240.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000037; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.187.151.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000038; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.20.213.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000039; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.203.210.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000040; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.226.249.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000045; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.227.118.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000046; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.231.14.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000047; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.240.211.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000048; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.245.10.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000049; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.245.204.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000050; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.247.164.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000051; rev:1;)

Recently removed entries

  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.53.15.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000021; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.53.15.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000022; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.68.74.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000023; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.101.85.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000024; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.101.85.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000025; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.106.250.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000026; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.116.190.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000027; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.125.163.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000028; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.153.93.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000029; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.154.90.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000030; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.117.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000033; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.128.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000034; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.18.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000035; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.164.200.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000036; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.168.67.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000037; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.179.240.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000038; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.187.151.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000039; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.20.213.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000040; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.227.118.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000045; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.231.14.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000046; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.236.133.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100000047; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.236.135.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000048; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.240.211.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000049; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.245.10.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000050; rev:1;)
  • alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.245.204.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000051; rev:1;)
Scroll to Top