################################################################ # ThreatFox IOCs: Suricata rules # # Last updated: 2025-02-19 00:01:43 UTC # # # # Terms Of Use: https://threatfox.abuse.ch/faq/#tos # # For questions please contact threatfox [at] abuse.ch # ################################################################ # alert tcp $HOME_NET any -> [15.156.204.223] 1521 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414835/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_19; classtype:trojan-activity; sid:91414835; rev:1;) alert tcp $HOME_NET any -> [212.224.86.165] 80 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414834/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_19; classtype:trojan-activity; sid:91414834; rev:1;) alert tcp $HOME_NET any -> [66.42.94.244] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414833/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_19; classtype:trojan-activity; sid:91414833; rev:1;) alert tcp $HOME_NET any -> [176.65.142.198] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414832/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_19; classtype:trojan-activity; sid:91414832; rev:1;) alert tcp $HOME_NET any -> [45.76.25.115] 7443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414831/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_19; classtype:trojan-activity; sid:91414831; rev:1;) alert tcp $HOME_NET any -> [31.57.166.130] 6606 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414828/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_19; classtype:trojan-activity; sid:91414828; rev:1;) alert tcp $HOME_NET any -> [31.57.166.130] 7707 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414829/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_19; classtype:trojan-activity; sid:91414829; rev:1;) alert tcp $HOME_NET any -> [31.57.166.130] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414830/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_19; classtype:trojan-activity; sid:91414830; rev:1;) alert tcp $HOME_NET any -> [65.109.115.25] 6000 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414827/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_19; classtype:trojan-activity; sid:91414827; rev:1;) alert tcp $HOME_NET any -> [151.236.16.143] 8888 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414826/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_19; classtype:trojan-activity; sid:91414826; rev:1;) alert tcp $HOME_NET any -> [38.60.199.60] 443 (msg:"ThreatFox ShadowPad botnet C2 traffic (ip:port - confidence level: 90%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414825/; target:src_ip; metadata: confidence_level 90, first_seen 2025_02_19; classtype:trojan-activity; sid:91414825; rev:1;) alert tcp $HOME_NET any -> [194.164.168.130] 80 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414824/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_19; classtype:trojan-activity; sid:91414824; rev:1;) alert tcp $HOME_NET any -> [18.216.198.113] 443 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414823/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_19; classtype:trojan-activity; sid:91414823; rev:1;) alert tcp $HOME_NET any -> [47.104.71.84] 8090 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414821/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_19; classtype:trojan-activity; sid:91414821; rev:1;) alert tcp $HOME_NET any -> [47.239.148.18] 81 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414822/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_19; classtype:trojan-activity; sid:91414822; rev:1;) alert tcp $HOME_NET any -> [1.94.185.254] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414820/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_19; classtype:trojan-activity; sid:91414820; rev:1;) alert tcp $HOME_NET any -> [196.251.81.57] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414819/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_19; classtype:trojan-activity; sid:91414819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/12884306.php"; depth:13; nocase; http.host; content:"sigmabioaef.atwebpages.com"; depth:26; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414816/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/5f596469.php"; depth:13; nocase; http.host; content:"a1085424.xsph.ru"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414815/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414815; rev:1;) alert tcp $HOME_NET any -> [78.167.159.180] 443 (msg:"ThreatFox QakBot botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414814/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_18; classtype:trojan-activity; sid:91414814; rev:1;) alert tcp $HOME_NET any -> [43.141.132.14] 10250 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414813/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_18; classtype:trojan-activity; sid:91414813; rev:1;) alert tcp $HOME_NET any -> [34.245.206.244] 1912 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414812/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_18; classtype:trojan-activity; sid:91414812; rev:1;) alert tcp $HOME_NET any -> [2.89.27.110] 995 (msg:"ThreatFox QakBot botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414811/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_18; classtype:trojan-activity; sid:91414811; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"frtgg14th.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414810/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414810; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"eightjj8sr.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414801/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414801; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"frtncc14vs.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414802/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414802; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"frtnhh14pn.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414803/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414803; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"twntjj20sr.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414804/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414804; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"tnwnthh20pn.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414805/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414805; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"fivgg5sb.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414806/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414806; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"frtggsb.top"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414807/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414807; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"thrtgg13sb.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414808/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414808; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"twntgg20th.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414809/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414809; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"twntpp20sb.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414800/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414800; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"onehh1pn.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414798/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414798; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"frtnpp14sb.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414797/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414797; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"tenjj10sr.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414795/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414795; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sixjj6sr.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414794/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414794; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"twntcc20vs.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414793/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"smoothsprin.click"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414792/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414792; rev:1;) alert tcp $HOME_NET any -> [176.100.37.204] 1337 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414789/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414789; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"smoothsprin.click"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414788/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414788; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"a1040668.xsph.ru"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414787/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414787; rev:1;) alert tcp $HOME_NET any -> [46.246.12.2] 9000 (msg:"ThreatFox DCRat botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414785/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414785; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"a1080277.xsph.ru"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414786/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414786; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"a1080822.xsph.ru"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414784/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414784; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"a1080799.xsph.ru"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414783/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414783; rev:1;) alert tcp $HOME_NET any -> [212.224.86.165] 443 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414782/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414782; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"f1068264.xsph.ru"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414780/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414780; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ct18031.tw1.ru"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414781/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414781; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"f1081725.xsph.ru"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414779/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414779; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"f1080509.xsph.ru"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414778/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414778; rev:1;) alert tcp $HOME_NET any -> [65.109.226.131] 7443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414777/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414777; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"fivecc5vs.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414776/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414776; rev:1;) alert tcp $HOME_NET any -> [128.90.103.206] 9999 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414774/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414774; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sixcc6vs.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414775/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414775; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"thrtcc13vs.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414773/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414773; rev:1;) alert tcp $HOME_NET any -> [209.38.192.61] 8080 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414772/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414772; rev:1;) alert tcp $HOME_NET any -> [185.202.173.24] 5824 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414771/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414771; rev:1;) alert tcp $HOME_NET any -> [204.10.161.144] 2404 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414770/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mayl/saver/gravadados.php"; depth:26; nocase; http.host; content:"auth.rastreiotransporte4f.com"; depth:29; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414765/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/securelowvoiddbflower/7polldownloadsuploads/universalmariadb/line5_/wpdle/centralmultiapi/windows/testeternaluploadspublic/pipebasepipemulti/uploads/dle/image/httpupdateprocessdbbase.php"; depth:187; nocase; http.host; content:"185.180.230.239"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414764/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414764; rev:1;) alert tcp $HOME_NET any -> [91.149.253.11] 42069 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414763/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414763; rev:1;) alert tcp $HOME_NET any -> [87.251.79.180] 12345 (msg:"ThreatFox Bashlite botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414760/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414760; rev:1;) alert tcp $HOME_NET any -> [209.141.57.97] 23 (msg:"ThreatFox Bashlite botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414761/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414761; rev:1;) alert tcp $HOME_NET any -> [205.185.115.242] 12345 (msg:"ThreatFox Bashlite botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414762/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414762; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.jmnfp.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414756/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414756; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 75%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/never.m4a"; depth:10; nocase; http.host; content:"u1.rejoincartridge.shop"; depth:23; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414757/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_18; classtype:trojan-activity; sid:91414757; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.jmnfp.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414759/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414759; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"yuzbook.info"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414758/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414758; rev:1;) alert tcp $HOME_NET any -> [185.74.222.38] 443 (msg:"ThreatFox Bashlite botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414755/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414755; rev:1;) alert tcp $HOME_NET any -> [18.218.191.48] 53 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414754/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_18; classtype:trojan-activity; sid:91414754; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"dns.windowsupdate.cloud"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414753/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_18; classtype:trojan-activity; sid:91414753; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; nocase; http.host; content:"59.94.127.152"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414752/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414752; rev:1;) alert tcp $HOME_NET any -> [45.90.219.246] 7968 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414751/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414751; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nta4mzixmjdkyznj/"; depth:18; nocase; http.host; content:"edfwn923sfdml237vm90sdl23k.com"; depth:30; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414739/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_18; classtype:trojan-activity; sid:91414739; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nta4mzixmjdkyznj/"; depth:18; nocase; http.host; content:"823jkfs4829nk48kef742kj675.com"; depth:30; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414740/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_18; classtype:trojan-activity; sid:91414740; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nta4mzixmjdkyznj/"; depth:18; nocase; http.host; content:"sdglk33498knsf32667sfknwfr.com"; depth:30; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414741/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_18; classtype:trojan-activity; sid:91414741; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nta4mzixmjdkyznj/"; depth:18; nocase; http.host; content:"952dsjk47kf73ls23k489klfdd.com"; depth:30; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414742/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_18; classtype:trojan-activity; sid:91414742; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nta4mzixmjdkyznj/"; depth:18; nocase; http.host; content:"nzxvjej7337bjsdl232nsdlsfa.com"; depth:30; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414743/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_18; classtype:trojan-activity; sid:91414743; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nta4mzixmjdkyznj/"; depth:18; nocase; http.host; content:"2348sdks230df834sd03272nsd.com"; depth:30; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414744/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_18; classtype:trojan-activity; sid:91414744; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2zimdm2y2y5zdm1/"; depth:18; nocase; http.host; content:"edfwn923sacasfdml237vm90sdl23k.com"; depth:34; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414745/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_18; classtype:trojan-activity; sid:91414745; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2zimdm2y2y5zdm1/"; depth:18; nocase; http.host; content:"2dd6d23b6061211f9813c0c4d18f2a5f.com"; depth:36; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414746/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_18; classtype:trojan-activity; sid:91414746; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2zimdm2y2y5zdm1/"; depth:18; nocase; http.host; content:"3edfwn923sacasfdml237vm90sdl23k.com"; depth:35; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414747/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_18; classtype:trojan-activity; sid:91414747; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2zimdm2y2y5zdm1/"; depth:18; nocase; http.host; content:"5edfwn923sacasfdml237vm90sdl23k.com"; depth:35; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414748/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_18; classtype:trojan-activity; sid:91414748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/n2zimdm2y2y5zdm1/"; depth:18; nocase; http.host; content:"7edfwn923sacasfdml237vm90sdl23k.com"; depth:35; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414749/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_18; classtype:trojan-activity; sid:91414749; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nta4mzixmjdkyznj/"; depth:18; nocase; http.host; content:"8edfwn923sacasfdml237vm90sdl23k.com"; depth:35; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414750/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_18; classtype:trojan-activity; sid:91414750; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nta4mzixmjdkyznj/"; depth:18; nocase; http.host; content:"3267hsd32jke47s3j402j4302h.com"; depth:30; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414738/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_18; classtype:trojan-activity; sid:91414738; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nta4mzixmjdkyznj/"; depth:18; nocase; http.host; content:"193.143.1.77"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414736/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_18; classtype:trojan-activity; sid:91414736; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.jtfsn.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414735/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414735; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/nta4mzixmjdkyznj/"; depth:18; nocase; http.host; content:"kjgtg3242ioh254kjsobhkj353.com"; depth:30; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414737/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_18; classtype:trojan-activity; sid:91414737; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.jtfsn.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414734/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414734; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"api.kaf.jp.eu.org"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414733/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414733; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"api.kaf.jp.eu.org"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414732/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414732; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"usdgyzjey4h.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414726/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414726; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"mioasfybz7y4.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414727/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414727; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"nfuagy7fgus.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414728/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414728; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"l284afj165tqz51.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414729/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414729; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"icciilhkbdgjggn.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414730/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414730; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"anccvfsrkauefoh.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414731/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414731; rev:1;) alert tcp $HOME_NET any -> [82.29.61.37] 1024 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414711/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_18; classtype:trojan-activity; sid:91414711; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"kdljlignmgemecf.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414725/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414725; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"comepreventsur.shop"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414709/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414709; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"fraildinerip.shop"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414710/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414710; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"crackerdisccre.shop"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414707/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414707; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"creppugler.shop"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414708/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414708; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"forcehoppen.shop"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414706/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414706; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"erracitofge.shop"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414705/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414705; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"carrofiwi.shop"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414704/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414704; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"actleavvek.shop"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414702/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414702; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cloudsbeeseez.shop"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414703/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414703; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"bucketrenouv.shop"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414700/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414700; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cherriestubb.shop"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414701/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414701; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"closedsaccke.shop"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414698/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414698; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cavemelodice.shop"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414699/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414699; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"achievesalutto.shop"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414695/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414695; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cobwebymitk.shop"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414697/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414697; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"beatgoattk.shop"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414696/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414696; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ablekettled.shop"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414693/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414693; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"avoidshirru.shop"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414694/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414694; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"busheprettuv.shop"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414692/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414692; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"comepreventsur.shop"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414690/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414690; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"fraildinerip.shop"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414691/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414691; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"creppugler.shop"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414689/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414689; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"forcehoppen.shop"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414687/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"crackerdisccre.shop"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414688/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"erracitofge.shop"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414686/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"carrofiwi.shop"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414685/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"cloudsbeeseez.shop"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414684/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"actleavvek.shop"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414683/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"cherriestubb.shop"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414682/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414682; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"bucketrenouv.shop"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414681/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414681; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"closedsaccke.shop"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414679/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414679; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"cavemelodice.shop"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414680/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414680; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"cobwebymitk.shop"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414678/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414678; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"beatgoattk.shop"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414677/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414677; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"achievesalutto.shop"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414676/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414676; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"avoidshirru.shop"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414675/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414675; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"busheprettuv.shop"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414673/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414673; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"ablekettled.shop"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414674/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414674; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"urbjanjungle.tech"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414672/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414672; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/lol.zip"; depth:8; nocase; http.host; content:"poormet.com"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414670/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414670; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"certificate.hypnotherapy-training.co.nz"; depth:39; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414671/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414671; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/work/file.php"; depth:14; nocase; http.host; content:"mammeporche.top"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414669/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/work/index.php"; depth:15; nocase; http.host; content:"mammeporche.top"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414668/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414668; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"mammeporche.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414667/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414667; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/work/original.js"; depth:17; nocase; http.host; content:"mammeporche.top"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414666/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414666; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"lestagames.world"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414665/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414665; rev:1;) alert tcp $HOME_NET any -> [213.148.26.193] 3790 (msg:"ThreatFox Meterpreter botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414664/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414664; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.psjvt.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414662/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414662; rev:1;) alert tcp $HOME_NET any -> [193.143.1.19] 9876 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414663/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414663; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.psjvt.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414661/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414661; rev:1;) alert tcp $HOME_NET any -> [43.133.36.25] 8082 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414724/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414724; rev:1;) alert tcp $HOME_NET any -> [51.81.239.186] 9999 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414723/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414723; rev:1;) alert tcp $HOME_NET any -> [39.106.75.37] 80 (msg:"ThreatFox MimiKatz botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414722/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414722; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"unruffled-mccarthy.45-143-99-196.plesk.page"; depth:43; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414721/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414721; rev:1;) alert tcp $HOME_NET any -> [45.143.99.196] 80 (msg:"ThreatFox ERMAC botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414720/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414720; rev:1;) alert tcp $HOME_NET any -> [93.232.97.253] 82 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414719/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414719; rev:1;) alert tcp $HOME_NET any -> [116.203.56.216] 2222 (msg:"ThreatFox Quasar RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414718/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414718; rev:1;) alert tcp $HOME_NET any -> [54.224.124.72] 7443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414717/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414717; rev:1;) alert tcp $HOME_NET any -> [188.127.231.164] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414716/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414716; rev:1;) alert tcp $HOME_NET any -> [94.237.52.233] 8090 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414715/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414715; rev:1;) alert tcp $HOME_NET any -> [185.196.10.153] 5000 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414714/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414714; rev:1;) alert tcp $HOME_NET any -> [139.180.193.31] 887 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414712/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414712; rev:1;) alert tcp $HOME_NET any -> [43.224.227.209] 8888 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414713/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414713; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.ltxgh.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414658/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414658; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.ltxgh.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414659/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414659; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"rapiddevapi.com"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414660/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414660; rev:1;) alert tcp $HOME_NET any -> [52.149.122.11] 80 (msg:"ThreatFox BianLian botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414657/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414657; rev:1;) alert tcp $HOME_NET any -> [76.223.125.223] 10081 (msg:"ThreatFox Kaiji botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414656/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414656; rev:1;) alert tcp $HOME_NET any -> [45.150.34.182] 8089 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414655/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414655; rev:1;) alert tcp $HOME_NET any -> [185.49.126.235] 1999 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414654/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414654; rev:1;) alert tcp $HOME_NET any -> [195.133.5.224] 443 (msg:"ThreatFox ShadowPad botnet C2 traffic (ip:port - confidence level: 90%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414653/; target:src_ip; metadata: confidence_level 90, first_seen 2025_02_18; classtype:trojan-activity; sid:91414653; rev:1;) alert tcp $HOME_NET any -> [43.163.87.97] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414652/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414652; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.hdfkc.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414621/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414621; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.hdfkc.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414622/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414622; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/supershell/login/"; depth:18; nocase; http.host; content:"45.207.197.39"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414635/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414635; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fixuplink/application-patch/daily-2025-01/sysmender_connector.php"; depth:66; nocase; http.host; content:"fixuplink.com"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414650/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414650; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pythondbprivate.php"; depth:20; nocase; http.host; content:"285857cm.nyanyash.ru"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414651/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414651; rev:1;) alert tcp $HOME_NET any -> [64.95.11.106] 8888 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414649/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_18; classtype:trojan-activity; sid:91414649; rev:1;) alert tcp $HOME_NET any -> [31.184.196.130] 8843 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414648/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_18; classtype:trojan-activity; sid:91414648; rev:1;) alert tcp $HOME_NET any -> [3.160.199.180] 443 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414647/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_18; classtype:trojan-activity; sid:91414647; rev:1;) alert tcp $HOME_NET any -> [116.204.34.3] 8443 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414646/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_18; classtype:trojan-activity; sid:91414646; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"newgoodthingsforkbhh.duckdns.org"; depth:32; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414645/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414645; rev:1;) alert tcp $HOME_NET any -> [111.119.235.231] 5555 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414644/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414644; rev:1;) alert tcp $HOME_NET any -> [38.55.199.105] 8080 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414643/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414643; rev:1;) alert tcp $HOME_NET any -> [86.106.87.158] 26935 (msg:"ThreatFox BianLian botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414642/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414642; rev:1;) alert tcp $HOME_NET any -> [5.255.98.216] 443 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414641/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414641; rev:1;) alert tcp $HOME_NET any -> [13.48.55.8] 7443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414640/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414640; rev:1;) alert tcp $HOME_NET any -> [193.26.115.52] 7707 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414639/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414639; rev:1;) alert tcp $HOME_NET any -> [95.111.215.157] 4443 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414638/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414638; rev:1;) alert tcp $HOME_NET any -> [194.59.31.30] 3939 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414637/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414637; rev:1;) alert tcp $HOME_NET any -> [110.41.131.240] 8888 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414636/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414636; rev:1;) alert tcp $HOME_NET any -> [95.217.243.100] 443 (msg:"ThreatFox Vidar botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414632/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414632; rev:1;) alert tcp $HOME_NET any -> [95.217.245.74] 443 (msg:"ThreatFox Vidar botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414633/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414633; rev:1;) alert tcp $HOME_NET any -> [116.202.180.73] 443 (msg:"ThreatFox Vidar botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414634/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414634; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ftp.dijiafuzhu.xyz"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414630/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414630; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ftp.kaf.jp.eu.org"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414631/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414631; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"95.217.243.100"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414626/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414626; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"95.217.245.74"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414627/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414627; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"ftp.kaf.jp.eu.org"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414628/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414628; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"ftp.dijiafuzhu.xyz"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414629/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414629; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/profiles/76561199828130190"; depth:27; nocase; http.host; content:"steamcommunity.com"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414624/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414624; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/g02f04"; depth:7; nocase; http.host; content:"t.me"; depth:4; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414625/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414625; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/b3717072.php"; depth:13; nocase; http.host; content:"a1085017.xsph.ru"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414623/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414623; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"mike-second.gl.at.ply.gg"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414620/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414620; rev:1;) alert tcp $HOME_NET any -> [116.251.133.7] 37593 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414619/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414619; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/zx6dukf9"; depth:13; nocase; http.host; content:"pastebin.com"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414618/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414618; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"service-cyuasu6k-1319584009.nj.tencentapigw.com"; depth:47; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414617/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414617; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"nope-it-30183.portmap.host"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414616/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414616; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/"; depth:10; nocase; http.host; content:"immo-etoiles.fr"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414615/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414615; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"boldquestq.cyou"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414614/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414614; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"impactsupport.world"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414613/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414613; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"nestlecompany.world"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414612/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414612; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"lompappojumm.click"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414611/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414611; rev:1;) alert tcp $HOME_NET any -> [190.44.65.246] 81 (msg:"ThreatFox Xtreme RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414610/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414610; rev:1;) alert tcp $HOME_NET any -> [43.143.35.118] 50050 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414609/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414609; rev:1;) alert tcp $HOME_NET any -> [121.141.37.193] 6000 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414607/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414607; rev:1;) alert tcp $HOME_NET any -> [54.177.89.187] 12162 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414608/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414608; rev:1;) alert tcp $HOME_NET any -> [155.138.214.192] 31337 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414604/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414604; rev:1;) alert tcp $HOME_NET any -> [46.235.229.89] 9001 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414605/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414605; rev:1;) alert tcp $HOME_NET any -> [163.172.234.31] 7443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414606/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414606; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.fvqxp.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414595/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.fvqxp.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414596/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414596; rev:1;) alert tcp $HOME_NET any -> [43.162.121.147] 5001 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414603/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414603; rev:1;) alert tcp $HOME_NET any -> [122.114.169.63] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414602/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414602; rev:1;) alert tcp $HOME_NET any -> [139.180.193.31] 4433 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414601/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414601; rev:1;) alert tcp $HOME_NET any -> [167.114.2.2] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414598/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414598; rev:1;) alert tcp $HOME_NET any -> [137.184.190.241] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414599/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414599; rev:1;) alert tcp $HOME_NET any -> [47.94.200.115] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414600/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414600; rev:1;) alert tcp $HOME_NET any -> [23.97.56.187] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414597/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414597; rev:1;) alert tcp $HOME_NET any -> [192.210.150.24] 5590 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414594/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_18; classtype:trojan-activity; sid:91414594; rev:1;) alert tcp $HOME_NET any -> [185.208.156.45] 2404 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414593/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_18; classtype:trojan-activity; sid:91414593; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.lmdgg.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414590/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414590; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.lmdgg.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414592/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414592; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/limonswat.php"; depth:14; nocase; http.host; content:"93.123.84.246"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414591/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414591; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/art.php"; depth:8; nocase; http.host; content:"waveschurch.xyz"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414588/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414588; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/art.php"; depth:8; nocase; http.host; content:"vasebox.art"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414589/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414589; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.kpwlp.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414587/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414587; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.kpwlp.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414586/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.rlcbb.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414585/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414585; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.rlcbb.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414584/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414584; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"4399.canlonggame.com"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414551/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414551; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"unknown.serveblog.net"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414552/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414552; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 90%)"; dns_query; content:"xeaefryx.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414553/; target:src_ip; metadata: confidence_level 90, first_seen 2025_02_18; classtype:trojan-activity; sid:91414553; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"liftasoul.shop"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414554/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414554; rev:1;) alert tcp $HOME_NET any -> [96.126.112.85] 51606 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414556/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414556; rev:1;) alert tcp $HOME_NET any -> [139.99.23.210] 1000 (msg:"ThreatFox DCRat botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414555/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414555; rev:1;) alert tcp $HOME_NET any -> [156.244.11.6] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414557/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414557; rev:1;) alert tcp $HOME_NET any -> [198.74.55.179] 502 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414558/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414558; rev:1;) alert tcp $HOME_NET any -> [154.205.147.234] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414559/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414559; rev:1;) alert tcp $HOME_NET any -> [156.244.0.116] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414560/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414560; rev:1;) alert tcp $HOME_NET any -> [182.61.19.58] 60000 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414562/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414562; rev:1;) alert tcp $HOME_NET any -> [154.205.158.27] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414561/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414561; rev:1;) alert tcp $HOME_NET any -> [101.133.146.66] 60000 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414563/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414563; rev:1;) alert tcp $HOME_NET any -> [18.216.30.157] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414564/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414564; rev:1;) alert tcp $HOME_NET any -> [165.227.39.97] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414565/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414565; rev:1;) alert tcp $HOME_NET any -> [52.58.153.129] 443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414566/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414566; rev:1;) alert tcp $HOME_NET any -> [159.203.53.6] 443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414567/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414567; rev:1;) alert tcp $HOME_NET any -> [74.48.175.44] 8080 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414568/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414568; rev:1;) alert tcp $HOME_NET any -> [13.50.119.113] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414569/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414569; rev:1;) alert tcp $HOME_NET any -> [35.240.13.130] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414570/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414570; rev:1;) alert tcp $HOME_NET any -> [129.80.179.228] 443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414571/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414571; rev:1;) alert tcp $HOME_NET any -> [3.0.103.25] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414572/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414572; rev:1;) alert tcp $HOME_NET any -> [183.82.122.21] 443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414573/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414573; rev:1;) alert tcp $HOME_NET any -> [137.184.57.51] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414574/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414574; rev:1;) alert tcp $HOME_NET any -> [65.1.134.76] 8443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414576/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414576; rev:1;) alert tcp $HOME_NET any -> [185.62.75.170] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414575/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414575; rev:1;) alert tcp $HOME_NET any -> [3.86.157.41] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414577/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414577; rev:1;) alert tcp $HOME_NET any -> [138.201.19.103] 3335 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414579/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414579; rev:1;) alert tcp $HOME_NET any -> [5.223.54.91] 443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414578/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414578; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"www.mail.www.1ogln.com"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414580/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414580; rev:1;) alert tcp $HOME_NET any -> [185.7.214.51] 418 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414582/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414582; rev:1;) alert tcp $HOME_NET any -> [185.7.214.51] 417 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414473/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414473; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.hbskw.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414474/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414474; rev:1;) alert tcp $HOME_NET any -> [185.147.125.146] 431 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414475/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414475; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"impactsupport.world"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414476/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414476; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.hbskw.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414477/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414477; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"tattoobg.com"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414478/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414478; rev:1;) alert tcp $HOME_NET any -> [193.143.1.5] 431 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414479/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414479; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"balancedzlife.tech"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414495/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414495; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"pgldrop24.pro"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414496/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414496; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"gratefulheartx.tech"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414480/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414480; rev:1;) alert tcp $HOME_NET any -> [185.147.125.146] 426 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414503/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414503; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"bellthinkyj28.help"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414504/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414504; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"patchpreseh.help"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414505/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414505; rev:1;) alert tcp $HOME_NET any -> [185.147.125.147] 424 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414506/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414506; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"bellthinkyj28.help"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414507/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414507; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"patchpreseh.help"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414508/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414508; rev:1;) alert tcp $HOME_NET any -> [193.143.1.5] 423 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414510/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414510; rev:1;) alert tcp $HOME_NET any -> [185.215.113.51] 80 (msg:"ThreatFox Lumma Stealer payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414511/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414511; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"nestlecompany.world"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414509/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414509; rev:1;) alert tcp $HOME_NET any -> [185.7.214.51] 420 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414514/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414514; rev:1;) alert tcp $HOME_NET any -> [185.147.125.146] 425 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414529/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414529; rev:1;) alert tcp $HOME_NET any -> [185.7.214.51] 423 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414525/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414525; rev:1;) alert tcp $HOME_NET any -> [185.42.12.45] 428 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414526/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414526; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/supershell/login/"; depth:18; nocase; http.host; content:"115.120.242.123"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414550/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414550; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/supershell/login/"; depth:18; nocase; http.host; content:"119.45.118.52"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414549/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414549; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/supershell/login/"; depth:18; nocase; http.host; content:"196.251.90.44"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414530/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414530; rev:1;) alert tcp $HOME_NET any -> [193.32.162.38] 3778 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414532/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414532; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"naiftheking.xyz"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414583/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_18; classtype:trojan-activity; sid:91414583; rev:1;) alert tcp $HOME_NET any -> [45.138.16.50] 4000 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414581/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414581; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/e6cb1c8fc7cd1659.php"; depth:21; nocase; http.host; content:"ecozessentials.com"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414548/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414548; rev:1;) alert tcp $HOME_NET any -> [84.200.154.125] 443 (msg:"ThreatFox PoshC2 botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414547/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414547; rev:1;) alert tcp $HOME_NET any -> [54.227.76.173] 8081 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414546/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414546; rev:1;) alert tcp $HOME_NET any -> [46.246.6.7] 9000 (msg:"ThreatFox DCRat botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414545/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414545; rev:1;) alert tcp $HOME_NET any -> [157.20.182.52] 4449 (msg:"ThreatFox Venom RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414544/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414544; rev:1;) alert tcp $HOME_NET any -> [156.253.228.55] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414542/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414542; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ec2-54-251-124-7.ap-southeast-1.compute.amazonaws.com"; depth:53; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414543/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414543; rev:1;) alert tcp $HOME_NET any -> [193.26.115.52] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414540/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414540; rev:1;) alert tcp $HOME_NET any -> [69.48.202.241] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414541/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414541; rev:1;) alert tcp $HOME_NET any -> [119.45.118.52] 8888 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414539/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414539; rev:1;) alert tcp $HOME_NET any -> [112.121.164.202] 8080 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414538/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414538; rev:1;) alert tcp $HOME_NET any -> [191.101.51.149] 2404 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414537/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414537; rev:1;) alert tcp $HOME_NET any -> [181.235.4.255] 2404 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414534/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414534; rev:1;) alert tcp $HOME_NET any -> [94.156.227.92] 2404 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414535/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414535; rev:1;) alert tcp $HOME_NET any -> [185.196.10.153] 2404 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414536/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414536; rev:1;) alert tcp $HOME_NET any -> [91.223.70.6] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414533/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414533; rev:1;) alert tcp $HOME_NET any -> [147.185.221.25] 44311 (msg:"ThreatFox NjRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414531/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414531; rev:1;) alert tcp $HOME_NET any -> [123.30.186.249] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414528/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_18; classtype:trojan-activity; sid:91414528; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"google.baobecgiang.net"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414527/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_18; classtype:trojan-activity; sid:91414527; rev:1;) alert tcp $HOME_NET any -> [194.113.74.174] 8000 (msg:"ThreatFox MimiKatz botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414524/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414524; rev:1;) alert tcp $HOME_NET any -> [152.42.230.191] 80 (msg:"ThreatFox Bashlite botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414523/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414523; rev:1;) alert tcp $HOME_NET any -> [193.35.17.242] 8080 (msg:"ThreatFox ERMAC botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414522/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414522; rev:1;) alert tcp $HOME_NET any -> [13.208.165.189] 4746 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414521/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414521; rev:1;) alert tcp $HOME_NET any -> [181.162.178.164] 8080 (msg:"ThreatFox Quasar RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414520/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414520; rev:1;) alert tcp $HOME_NET any -> [52.74.224.241] 443 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414519/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414519; rev:1;) alert tcp $HOME_NET any -> [128.90.103.206] 2000 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414517/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414517; rev:1;) alert tcp $HOME_NET any -> [128.90.103.206] 5000 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414518/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414518; rev:1;) alert tcp $HOME_NET any -> [206.123.150.192] 2405 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414516/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_18; classtype:trojan-activity; sid:91414516; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6daefec2.php"; depth:13; nocase; http.host; content:"cj98865.tw1.ru"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414515/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414515; rev:1;) alert tcp $HOME_NET any -> [194.146.47.231] 1604 (msg:"ThreatFox DarkComet botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414513/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414513; rev:1;) alert tcp $HOME_NET any -> [120.26.1.102] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414512/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414512; rev:1;) alert tcp $HOME_NET any -> [70.31.125.14] 2222 (msg:"ThreatFox QakBot botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414502/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414502; rev:1;) alert tcp $HOME_NET any -> [5.83.218.75] 8080 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414501/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414501; rev:1;) alert tcp $HOME_NET any -> [23.97.56.187] 8888 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414500/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414500; rev:1;) alert tcp $HOME_NET any -> [172.111.160.104] 443 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414499/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414499; rev:1;) alert tcp $HOME_NET any -> [159.223.157.44] 443 (msg:"ThreatFox Eye Pyramid botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414498/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414498; rev:1;) alert tcp $HOME_NET any -> [13.37.236.177] 52959 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414497/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414497; rev:1;) alert tcp $HOME_NET any -> [13.38.4.197] 18245 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414494/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414494; rev:1;) alert tcp $HOME_NET any -> [157.20.182.32] 4449 (msg:"ThreatFox Venom RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414493/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414493; rev:1;) alert tcp $HOME_NET any -> [79.198.171.227] 4785 (msg:"ThreatFox Quasar RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414492/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414492; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ec2-18-143-214-68.ap-southeast-1.compute.amazonaws.com"; depth:54; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414491/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414491; rev:1;) alert tcp $HOME_NET any -> [13.213.149.14] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414490/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414490; rev:1;) alert tcp $HOME_NET any -> [179.13.9.42] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414488/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414488; rev:1;) alert tcp $HOME_NET any -> [192.30.241.217] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414489/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414489; rev:1;) alert tcp $HOME_NET any -> [23.97.56.187] 443 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414487/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414487; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"www.pinkandgreen87.info"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414485/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414485; rev:1;) alert tcp $HOME_NET any -> [196.251.118.49] 2404 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414486/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414486; rev:1;) alert tcp $HOME_NET any -> [181.131.219.42] 2404 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414483/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414483; rev:1;) alert tcp $HOME_NET any -> [192.3.243.143] 6878 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414484/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414484; rev:1;) alert tcp $HOME_NET any -> [196.251.89.152] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414481/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414481; rev:1;) alert tcp $HOME_NET any -> [196.251.118.160] 8443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414482/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414482; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.pvhqg.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414464/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414464; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.pvhqg.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414467/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414467; rev:1;) alert tcp $HOME_NET any -> [51.8.133.234] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414472/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414472; rev:1;) alert tcp $HOME_NET any -> [13.232.126.176] 636 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414471/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414471; rev:1;) alert tcp $HOME_NET any -> [43.165.133.147] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414470/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/art.php"; depth:8; nocase; http.host; content:"marketcalendar.icu"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414469/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414469; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/art.php"; depth:8; nocase; http.host; content:"windowart.xyz"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414468/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414468; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/art.php"; depth:8; nocase; http.host; content:"poisonstone.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414466/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414466; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/art.php"; depth:8; nocase; http.host; content:"cellaradvertisement.icu"; depth:23; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414465/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414465; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"lqalmpkebwpvdaf.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414300/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414300; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"jlltk5azih351g4.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414301/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414301; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"mieuyyzbv334s.top"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414299/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414299; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"3dijvbhfyutu34j.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414303/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414303; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"adanddcdjbdefml.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414302/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414302; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"yxrqxlvregipunw.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414304/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414304; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"hikcjbiklgabbfh.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414305/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414305; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"mgkwjihehqcknbp.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414306/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414306; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"amgfcnadnlkmlmd.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414307/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414307; rev:1;) alert tcp $HOME_NET any -> [185.147.125.145] 419 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414308/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414308; rev:1;) alert tcp $HOME_NET any -> [185.147.125.146] 430 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414309/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414309; rev:1;) alert tcp $HOME_NET any -> [185.147.125.147] 421 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414310/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414310; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"e4fdc0d3-eebe-4297-bc15-780796d8c861.cyqfuy.shop"; depth:48; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414311/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414311; rev:1;) alert tcp $HOME_NET any -> [193.143.1.5] 428 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414312/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414312; rev:1;) alert tcp $HOME_NET any -> [193.143.1.5] 426 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414313/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414313; rev:1;) alert tcp $HOME_NET any -> [185.42.12.45] 427 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414314/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.bzhzm.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414298/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414298; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.bzhzm.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414287/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414287; rev:1;) alert tcp $HOME_NET any -> [185.147.125.147] 417 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414278/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414278; rev:1;) alert tcp $HOME_NET any -> [185.243.96.115] 421 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414448/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414448; rev:1;) alert tcp $HOME_NET any -> [193.143.1.5] 429 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414449/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414449; rev:1;) alert tcp $HOME_NET any -> [185.42.12.45] 419 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414450/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414450; rev:1;) alert tcp $HOME_NET any -> [185.7.214.51] 424 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414315/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414315; rev:1;) alert tcp $HOME_NET any -> [185.147.125.147] 426 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414452/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414452; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"nestlecompany.world"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414457/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414457; rev:1;) alert tcp $HOME_NET any -> [185.42.12.45] 429 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414453/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414453; rev:1;) alert tcp $HOME_NET any -> [185.147.125.147] 422 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414454/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414454; rev:1;) alert tcp $HOME_NET any -> [193.143.1.5] 424 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414455/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414455; rev:1;) alert tcp $HOME_NET any -> [193.143.1.5] 420 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414456/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414456; rev:1;) alert tcp $HOME_NET any -> [185.243.96.115] 416 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414463/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414463; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"mail.wingsaviationacademy.in"; depth:28; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414462/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414462; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"my.salviatech.com"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414461/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414461; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"mail.cambodiatouristservice.com"; depth:31; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414460/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414460; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"misano.gestroom.it"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414459/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414459; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"sales.mypetapp.co.za"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414458/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414458; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"tour-agency-media.pages.dev"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414451/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414451; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"site-accessing.gl.at.ply.gg"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414447/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414447; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"eddy2024.ddns.net"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414445/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414445; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"eddy2025.ddns.net"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414446/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414446; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"levangiang2004-60241.portmap.io"; depth:31; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414444/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414444; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.weqpo.xyz"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414440/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414440; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.wub.lat"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414441/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414441; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.xilis.net"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414442/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414442; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.yshopva.xyz"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414443/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414443; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.nnot.xyz"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414420/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414420; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.oftstarters.net"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414421/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414421; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.oftware-download-42246.bond"; depth:31; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414422/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414422; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.om-exchange-nft743640.sbs"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414423/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414423; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.onstruction-services-27125.bond"; depth:35; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414424/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414424; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.ontentexclusive.shop"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414425/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414425; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.q-test-45673.bond"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414426/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414426; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.raffitishop.online"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414427/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414427; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.ramingfaith.shop"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414428/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414428; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.raphic-design-degree-15820.bond"; depth:35; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414429/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414429; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.razyfbteam.store"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414430/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414430; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.rls.xyz"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414431/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414431; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.rofesyonelwebtasarimi.online"; depth:32; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414432/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414432; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.sibot.tech"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414433/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414433; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.tbldg.world"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414434/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414434; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.uego.wtf"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414435/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414435; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.urasiindo4dpools.net"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414436/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414436; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.utomation-tools-92232.bond"; depth:30; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414437/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414437; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.utter-and-roof-cleaning.today"; depth:33; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414438/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414438; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.vplay.tech"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414439/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414439; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.ental-implants-49625.bond"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414399/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414399; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.esiarbet17.live"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414400/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414400; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.esignix.xyz"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414401/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414401; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.etayes.net"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414402/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414402; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.eyo.xyz"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414403/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414403; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.gjnp.info"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414404/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414404; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.honia.xyz"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414405/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414405; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.houxiaoxiao.online"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414406/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414406; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.ibit.xyz"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414407/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414407; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.ikart.xyz"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414408/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414408; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.ilefox.xyz"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414409/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414409; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.iloubloiu-im.monster"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414410/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414410; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.irect-mail.online"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414411/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414411; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.kysports.monster"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414412/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414412; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.lumber-jobs-54632.bond"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414413/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414413; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.mage2cut.xyz"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414414/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414414; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.mble.monster"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414415/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414415; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.meshthapa.pro"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414416/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414416; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.mwa.info"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414417/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414417; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.nfluencer-marketing-58813.bond"; depth:34; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414418/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414418; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.nfopayout.website"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414419/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414419; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.-ai.solutions"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414380/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414380; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.22201111.xyz"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414381/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414381; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.5l0bblb.xyz"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414382/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414382; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.78899.vip"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414383/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414383; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.agprime.life"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414384/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414384; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.ard-vale.net"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414385/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414385; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.arehouse-inventory-57386.bond"; depth:33; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414386/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414386; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.arktooll-es.store"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414387/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414387; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.chmollinger.info"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414388/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414388; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.chmvhic.shop"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414389/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414389; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.cline.xyz"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414390/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414390; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.e6s.lat"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414391/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414391; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.ealswithmeaning.net"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414392/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414392; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.ealthcare-trends-21256.bond"; depth:31; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414393/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414393; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.eekava.online"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414394/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414394; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.emu.xyz"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414395/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414395; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.enet.xyz"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414396/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414396; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.enpuk.info"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414397/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414397; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.ental-health-57875.bond"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414398/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414398; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.xilis.net"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414378/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414378; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.yshopva.xyz"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414379/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.rofesyonelwebtasarimi.online"; depth:32; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414368/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.sibot.tech"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414369/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.tbldg.world"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414370/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414370; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.uego.wtf"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414371/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.urasiindo4dpools.net"; depth:24; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414372/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414372; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.utomation-tools-92232.bond"; depth:30; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414373/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414373; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.utter-and-roof-cleaning.today"; depth:33; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414374/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414374; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.vplay.tech"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414375/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.weqpo.xyz"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414376/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414376; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.wub.lat"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414377/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414377; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.oftstarters.net"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414357/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414357; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.oftware-download-42246.bond"; depth:31; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414358/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414358; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.om-exchange-nft743640.sbs"; depth:29; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414359/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414359; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.onstruction-services-27125.bond"; depth:35; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414360/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414360; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.ontentexclusive.shop"; depth:24; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414361/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414361; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.q-test-45673.bond"; depth:21; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414362/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.raffitishop.online"; depth:22; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414363/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414363; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.ramingfaith.shop"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414364/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.raphic-design-degree-15820.bond"; depth:35; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414365/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.razyfbteam.store"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414366/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414366; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.rls.xyz"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414367/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.irect-mail.online"; depth:21; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414347/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414347; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.kysports.monster"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414348/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414348; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.lumber-jobs-54632.bond"; depth:26; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414349/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414349; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.mage2cut.xyz"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414350/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.mble.monster"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414351/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.meshthapa.pro"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414352/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414352; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.mwa.info"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414353/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.nfluencer-marketing-58813.bond"; depth:34; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414354/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414354; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.nfopayout.website"; depth:21; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414355/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414355; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.nnot.xyz"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414356/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414356; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.esiarbet17.live"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414336/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414336; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.esignix.xyz"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414337/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414337; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.etayes.net"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414338/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414338; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.eyo.xyz"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414339/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414339; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.gjnp.info"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414340/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414340; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.honia.xyz"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414341/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.houxiaoxiao.online"; depth:22; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414342/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414342; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.ibit.xyz"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414343/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414343; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.ikart.xyz"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414344/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414344; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.ilefox.xyz"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414345/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414345; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.iloubloiu-im.monster"; depth:24; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414346/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414346; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.e6s.lat"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414326/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.ealswithmeaning.net"; depth:23; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414327/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414327; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.ealthcare-trends-21256.bond"; depth:31; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414328/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.eekava.online"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414329/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.elfast-cruisetours.today"; depth:28; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414330/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.emu.xyz"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414331/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.enet.xyz"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414332/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414332; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.enpuk.info"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414333/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.ental-health-57875.bond"; depth:27; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414334/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.ental-implants-49625.bond"; depth:29; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414335/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.22201111.xyz"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414316/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.5l0bblb.xyz"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414317/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.78899.vip"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414318/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.agprime.life"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414319/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414319; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.ard-vale.net"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414320/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414320; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.arehouse-inventory-57386.bond"; depth:33; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414321/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414321; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.arktooll-es.store"; depth:21; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414322/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414322; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.chmollinger.info"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414323/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414323; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.chmvhic.shop"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414324/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414324; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a94w/"; depth:6; nocase; http.host; content:"www.cline.xyz"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414325/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414325; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"mail.lucprofessional.com.br"; depth:27; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414286/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"lucprofessional.grupomoltz.com.br"; depth:33; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414285/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414285; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"dev.gestroom.it"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414284/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414284; rev:1;) alert tcp $HOME_NET any -> [138.68.171.106] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414282/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414282; rev:1;) alert tcp $HOME_NET any -> [188.245.78.205] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414283/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414283; rev:1;) alert tcp $HOME_NET any -> [18.144.7.69] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414279/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414279; rev:1;) alert tcp $HOME_NET any -> [46.249.58.46] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414280/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414280; rev:1;) alert tcp $HOME_NET any -> [111.119.239.73] 5555 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414281/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414281; rev:1;) alert tcp $HOME_NET any -> [185.147.125.145] 418 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414276/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414276; rev:1;) alert tcp $HOME_NET any -> [185.147.125.146] 421 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414277/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414277; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.qvdch.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414269/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414269; rev:1;) alert tcp $HOME_NET any -> [185.243.96.115] 424 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414270/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414270; rev:1;) alert tcp $HOME_NET any -> [185.147.125.145] 417 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414271/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414271; rev:1;) alert tcp $HOME_NET any -> [185.147.125.147] 427 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414272/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414272; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.qvdch.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414273/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414273; rev:1;) alert tcp $HOME_NET any -> [185.42.12.45] 418 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414274/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414274; rev:1;) alert tcp $HOME_NET any -> [185.147.125.147] 420 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414275/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414275; rev:1;) alert tcp $HOME_NET any -> [193.143.1.5] 416 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414255/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414255; rev:1;) alert tcp $HOME_NET any -> [185.147.125.145] 424 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414264/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414264; rev:1;) alert tcp $HOME_NET any -> [149.28.17.188] 8443 (msg:"ThreatFox BianLian botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414268/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414268; rev:1;) alert tcp $HOME_NET any -> [5.188.230.69] 8080 (msg:"ThreatFox MimiKatz botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414267/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414267; rev:1;) alert tcp $HOME_NET any -> [57.181.102.240] 80 (msg:"ThreatFox Brute Ratel C4 botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414266/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414266; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"video.proxbotpy.com"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414265/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414265; rev:1;) alert tcp $HOME_NET any -> [191.96.207.168] 2004 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414262/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414262; rev:1;) alert tcp $HOME_NET any -> [23.94.126.207] 6606 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414263/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414263; rev:1;) alert tcp $HOME_NET any -> [45.76.177.203] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414260/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414260; rev:1;) alert tcp $HOME_NET any -> [191.96.207.168] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414261/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414261; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"knoxinvestmentandsales.com"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414259/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414259; rev:1;) alert tcp $HOME_NET any -> [114.116.224.35] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414258/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414258; rev:1;) alert tcp $HOME_NET any -> [38.55.194.251] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414256/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414256; rev:1;) alert tcp $HOME_NET any -> [47.129.34.49] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414257/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414257; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.bxqhq.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414252/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414252; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.bxqhq.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414253/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414253; rev:1;) alert tcp $HOME_NET any -> [193.143.1.5] 419 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414254/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414254; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.xjlkm.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414251/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414251; rev:1;) alert tcp $HOME_NET any -> [185.42.12.45] 420 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414243/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414243; rev:1;) alert tcp $HOME_NET any -> [185.147.125.145] 420 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414244/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414244; rev:1;) alert tcp $HOME_NET any -> [185.147.125.146] 419 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414245/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414245; rev:1;) alert tcp $HOME_NET any -> [185.243.96.115] 429 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414248/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414248; rev:1;) alert tcp $HOME_NET any -> [185.147.125.147] 428 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414246/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414246; rev:1;) alert tcp $HOME_NET any -> [185.42.12.45] 431 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414247/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414247; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.xjlkm.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414249/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414249; rev:1;) alert tcp $HOME_NET any -> [185.42.12.45] 426 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414250/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414250; rev:1;) alert tcp $HOME_NET any -> [185.7.214.51] 431 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414238/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414238; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.vwfbm.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414239/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414239; rev:1;) alert tcp $HOME_NET any -> [185.7.214.51] 421 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414240/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414240; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.vwfbm.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414241/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414241; rev:1;) alert tcp $HOME_NET any -> [193.143.1.5] 430 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414242/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414242; rev:1;) alert tcp $HOME_NET any -> [185.243.96.115] 426 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414237/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414237; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.hmccl.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414230/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414230; rev:1;) alert tcp $HOME_NET any -> [185.147.125.145] 430 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414231/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414231; rev:1;) alert tcp $HOME_NET any -> [185.7.214.51] 419 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414232/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414232; rev:1;) alert tcp $HOME_NET any -> [103.186.117.159] 48453 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414233/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414233; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.ngrdr.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414215/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414215; rev:1;) alert tcp $HOME_NET any -> [185.42.12.45] 423 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414216/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414216; rev:1;) alert tcp $HOME_NET any -> [185.147.125.146] 416 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414217/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414217; rev:1;) alert tcp $HOME_NET any -> [185.7.214.51] 416 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414218/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414218; rev:1;) alert tcp $HOME_NET any -> [185.7.214.51] 427 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414219/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414219; rev:1;) alert tcp $HOME_NET any -> [185.42.12.45] 417 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414220/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414220; rev:1;) alert tcp $HOME_NET any -> [185.42.12.45] 425 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414221/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414221; rev:1;) alert tcp $HOME_NET any -> [185.7.214.51] 425 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414227/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414227; rev:1;) alert tcp $HOME_NET any -> [185.243.96.115] 417 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414228/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414228; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.hmccl.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414229/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414229; rev:1;) alert tcp $HOME_NET any -> [204.76.203.175] 1962 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414222/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414222; rev:1;) alert tcp $HOME_NET any -> [217.195.153.175] 1962 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414223/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414223; rev:1;) alert tcp $HOME_NET any -> [204.76.203.188] 1962 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414224/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414224; rev:1;) alert tcp $HOME_NET any -> [204.76.203.173] 1962 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414225/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414225; rev:1;) alert tcp $HOME_NET any -> [204.76.203.172] 1962 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414226/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414226; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.ngrdr.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414214/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414214; rev:1;) alert tcp $HOME_NET any -> [185.7.214.51] 429 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414191/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414191; rev:1;) alert tcp $HOME_NET any -> [185.7.214.51] 422 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414192/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414192; rev:1;) alert tcp $HOME_NET any -> [185.147.125.147] 429 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414193/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414193; rev:1;) alert tcp $HOME_NET any -> [193.143.1.5] 427 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414194/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414194; rev:1;) alert tcp $HOME_NET any -> [185.147.125.145] 422 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414195/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414195; rev:1;) alert tcp $HOME_NET any -> [185.42.12.45] 422 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414196/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414196; rev:1;) alert tcp $HOME_NET any -> [185.147.125.146] 429 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414197/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414197; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"heavysnowday.net"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414198/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414198; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"heavysnowday.com"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414199/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/work/original.js"; depth:17; nocase; http.host; content:"cinaweine.shop"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414200/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414200; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"cinaweine.shop"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414201/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414201; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"devmodebeta.dev"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414202/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414202; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/work/index.php"; depth:15; nocase; http.host; content:"cinaweine.shop"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414203/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414203; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/work/file.php"; depth:14; nocase; http.host; content:"cinaweine.shop"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414204/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414204; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/333.zip"; depth:8; nocase; http.host; content:"verifiedtasks.com"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414205/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414205; rev:1;) alert tcp $HOME_NET any -> [185.147.125.147] 418 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414207/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414207; rev:1;) alert tcp $HOME_NET any -> [194.180.191.229] 443 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414206/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414206; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"dashboard.nzlifecoaching.com"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414208/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414208; rev:1;) alert tcp $HOME_NET any -> [91.211.250.95] 80 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414210/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414210; rev:1;) alert tcp $HOME_NET any -> [185.147.125.145] 421 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414209/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414209; rev:1;) alert tcp $HOME_NET any -> [185.7.214.51] 430 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414211/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414211; rev:1;) alert tcp $HOME_NET any -> [185.147.125.145] 425 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414213/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414213; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 60241 (msg:"ThreatFox Quasar RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414212/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414212; rev:1;) alert tcp $HOME_NET any -> [185.42.12.45] 416 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414182/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414182; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.xybdd.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414183/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414183; rev:1;) alert tcp $HOME_NET any -> [185.147.125.146] 424 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414184/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414184; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.xybdd.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414185/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414185; rev:1;) alert tcp $HOME_NET any -> [185.147.125.146] 427 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414186/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414186; rev:1;) alert tcp $HOME_NET any -> [185.243.96.115] 431 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414188/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414188; rev:1;) alert tcp $HOME_NET any -> [185.147.125.147] 416 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414187/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414187; rev:1;) alert tcp $HOME_NET any -> [185.243.96.115] 422 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414189/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414189; rev:1;) alert tcp $HOME_NET any -> [185.147.125.146] 417 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414190/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414190; rev:1;) alert tcp $HOME_NET any -> [185.147.125.145] 427 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414169/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414169; rev:1;) alert tcp $HOME_NET any -> [185.7.214.51] 428 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414170/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414170; rev:1;) alert tcp $HOME_NET any -> [185.147.125.147] 425 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414171/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414171; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 75%)"; dns_query; content:"endxlesspossi.tech"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414172/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414172; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 75%)"; dns_query; content:"stormlegue.com"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414176/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414176; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 75%)"; dns_query; content:"blast-hubs.com"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414177/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414177; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 75%)"; dns_query; content:"shiningrstars.help"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414173/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414173; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 75%)"; dns_query; content:"mercharena.biz"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414174/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414174; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 75%)"; dns_query; content:"generalmills.pro"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414175/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414175; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 75%)"; dns_query; content:"blastikcn.com"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414178/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414178; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 75%)"; dns_query; content:"nestlecompany.pro"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414179/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414179; rev:1;) alert tcp $HOME_NET any -> [185.147.125.147] 430 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414180/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414180; rev:1;) alert tcp $HOME_NET any -> [193.143.1.5] 422 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414181/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414181; rev:1;) alert tcp $HOME_NET any -> [185.147.125.145] 423 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414166/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414166; rev:1;) alert tcp $HOME_NET any -> [185.243.96.115] 430 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414165/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414165; rev:1;) alert tcp $HOME_NET any -> [185.243.96.115] 425 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414167/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414167; rev:1;) alert tcp $HOME_NET any -> [185.147.125.147] 419 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414168/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414168; rev:1;) alert tcp $HOME_NET any -> [185.147.125.146] 418 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414158/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414158; rev:1;) alert tcp $HOME_NET any -> [185.147.125.145] 431 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414159/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414159; rev:1;) alert tcp $HOME_NET any -> [193.143.1.5] 421 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414160/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414160; rev:1;) alert tcp $HOME_NET any -> [185.42.12.45] 424 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414161/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414161; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.fadwl.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414162/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414162; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.fadwl.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414163/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414163; rev:1;) alert tcp $HOME_NET any -> [185.147.125.146] 428 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414164/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414164; rev:1;) alert tcp $HOME_NET any -> [185.243.96.115] 427 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414156/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414156; rev:1;) alert tcp $HOME_NET any -> [185.7.214.51] 426 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414154/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414154; rev:1;) alert tcp $HOME_NET any -> [185.243.96.115] 419 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414155/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414155; rev:1;) alert tcp $HOME_NET any -> [185.147.125.145] 426 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414151/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414151; rev:1;) alert tcp $HOME_NET any -> [176.65.139.51] 6969 (msg:"ThreatFox XenoRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414152/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414152; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.pocbv.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414150/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414150; rev:1;) alert tcp $HOME_NET any -> [185.243.96.115] 418 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414153/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414153; rev:1;) alert tcp $HOME_NET any -> [185.147.125.145] 428 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414157/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414157; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.pocbv.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414146/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414146; rev:1;) alert tcp $HOME_NET any -> [185.243.96.115] 428 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414147/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414147; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/new/pws/pvqdq929bsx_a_d_m1n_a.php"; depth:34; nocase; http.host; content:"ddrtot.shop"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414148/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414148; rev:1;) alert tcp $HOME_NET any -> [185.243.96.115] 420 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414149/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414149; rev:1;) alert tcp $HOME_NET any -> [185.147.125.146] 420 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414131/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414131; rev:1;) alert tcp $HOME_NET any -> [185.42.12.45] 421 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414132/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414132; rev:1;) alert tcp $HOME_NET any -> [185.147.125.146] 423 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414133/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414133; rev:1;) alert tcp $HOME_NET any -> [193.143.1.5] 417 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414134/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414134; rev:1;) alert tcp $HOME_NET any -> [185.147.125.147] 431 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414139/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414139; rev:1;) alert tcp $HOME_NET any -> [185.42.12.45] 430 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414140/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414140; rev:1;) alert tcp $HOME_NET any -> [185.147.125.145] 429 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414141/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414141; rev:1;) alert tcp $HOME_NET any -> [185.147.125.147] 423 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414142/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414142; rev:1;) alert tcp $HOME_NET any -> [193.143.1.5] 418 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414143/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414143; rev:1;) alert tcp $HOME_NET any -> [185.243.96.115] 423 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414144/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414144; rev:1;) alert tcp $HOME_NET any -> [185.147.125.146] 422 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414145/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414145; rev:1;) alert tcp $HOME_NET any -> [45.202.32.56] 8000 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414138/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414138; rev:1;) alert tcp $HOME_NET any -> [38.55.199.105] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414137/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414137; rev:1;) alert tcp $HOME_NET any -> [144.91.92.132] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414136/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414136; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"nice.0818000.xyz"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414135/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414135; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"endxlesspossi.tech"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414124/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414124; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.wybps.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414125/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414125; rev:1;) alert tcp $HOME_NET any -> [5.83.218.12] 3778 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414126/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414126; rev:1;) alert tcp $HOME_NET any -> [194.85.251.68] 9931 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414127/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414127; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.wybps.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414128/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414128; rev:1;) alert tcp $HOME_NET any -> [193.143.1.5] 425 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414129/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414129; rev:1;) alert tcp $HOME_NET any -> [185.147.125.145] 416 (msg:"ThreatFox Tofsee botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414130/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414130; rev:1;) alert tcp $HOME_NET any -> [91.199.160.129] 80 (msg:"ThreatFox BianLian botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414123/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414123; rev:1;) alert tcp $HOME_NET any -> [122.114.169.63] 8080 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414122/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414122; rev:1;) alert tcp $HOME_NET any -> [54.64.181.201] 80 (msg:"ThreatFox Brute Ratel C4 botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414121/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414121; rev:1;) alert tcp $HOME_NET any -> [45.128.12.101] 8888 (msg:"ThreatFox Venom RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414120/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414120; rev:1;) alert tcp $HOME_NET any -> [23.152.0.81] 8080 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414119/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414119; rev:1;) alert tcp $HOME_NET any -> [83.196.195.34] 2408 (msg:"ThreatFox Quasar RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414118/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414118; rev:1;) alert tcp $HOME_NET any -> [173.249.52.37] 7443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414117/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414117; rev:1;) alert tcp $HOME_NET any -> [185.49.126.235] 7707 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414116/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414116; rev:1;) alert tcp $HOME_NET any -> [185.49.126.27] 7707 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414113/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414113; rev:1;) alert tcp $HOME_NET any -> [185.49.126.245] 7707 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414114/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414114; rev:1;) alert tcp $HOME_NET any -> [196.251.116.95] 7777 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414115/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414115; rev:1;) alert tcp $HOME_NET any -> [176.65.142.245] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414112/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414112; rev:1;) alert tcp $HOME_NET any -> [123.11.143.85] 5873 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414111/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414111; rev:1;) alert tcp $HOME_NET any -> [118.195.163.219] 8888 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414110/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414110; rev:1;) alert tcp $HOME_NET any -> [43.153.82.236] 443 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414109/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414109; rev:1;) alert tcp $HOME_NET any -> [157.20.182.51] 56872 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414108/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414108; rev:1;) alert tcp $HOME_NET any -> [172.94.9.167] 1962 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414107/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414107; rev:1;) alert tcp $HOME_NET any -> [47.108.131.159] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414106/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414106; rev:1;) alert tcp $HOME_NET any -> [154.64.252.57] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414105/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414105; rev:1;) alert tcp $HOME_NET any -> [1.118.34.218] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414104/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414104; rev:1;) alert tcp $HOME_NET any -> [1.118.34.218] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414103/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414103; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"ly.ardentlysqueamish.autos"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414082/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414082; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.kedkq.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414088/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414088; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.kedkq.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414087/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414087; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"xu1.dijiafuzhu.xyz"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414089/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414089; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"xu1.dijiafuzhu.xyz"; depth:18; nocase; reference:url, threatfox.abuse.ch/ioc/1414090/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414090; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"travel.image-gene-saver.it.com"; depth:30; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414091/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414091; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot7284285127:aafug_ek294atlka8lqmpqzedlvqi4bflre/"; depth:51; nocase; http.host; content:"api.telegram.org"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414102/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414102; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"portaal.com.my"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414101/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414101; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"facturacio.titoworld.com"; depth:24; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414100/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414100; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"mail.laborpartyjo.com"; depth:21; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414099/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414099; rev:1;) alert tcp $HOME_NET any -> [13.38.67.75] 6667 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414095/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414095; rev:1;) alert tcp $HOME_NET any -> [54.184.8.206] 993 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414096/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414096; rev:1;) alert tcp $HOME_NET any -> [190.10.11.37] 6000 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414097/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414097; rev:1;) alert tcp $HOME_NET any -> [54.177.88.161] 9333 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414098/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414098; rev:1;) alert tcp $HOME_NET any -> [37.12.3.194] 6001 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414094/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414094; rev:1;) alert tcp $HOME_NET any -> [64.95.10.13] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414093/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 75%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/new/pws/fre.php"; depth:16; nocase; http.host; content:"ddrtot.shop"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414092/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414092; rev:1;) alert tcp $HOME_NET any -> [169.239.129.45] 53 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414086/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414086; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"ns2.drgeregweg.ip-ddns.com"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414084/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414084; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"ns3.drgeregweg.ip-ddns.com"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414085/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414085; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"ns1.drgeregweg.ip-ddns.com"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414083/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414083; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.xomkb.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414080/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414080; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.xomkb.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414081/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414081; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6t4e.js"; depth:8; nocase; http.host; content:"vessweb.com"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414074/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414074; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"vessweb.com"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414075/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414075; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/js.php"; depth:7; nocase; http.host; content:"vessweb.com"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414076/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414076; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.jewsl.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414077/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414077; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.jewsl.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414078/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414078; rev:1;) alert tcp $HOME_NET any -> [5.182.226.142] 41127 (msg:"ThreatFox NjRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414079/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414079; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.ruqhl.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414061/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414061; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.ruqhl.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414062/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414062; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"mercharena.biz"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414063/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414063; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/supershell/login/"; depth:18; nocase; http.host; content:"104.214.176.148"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414071/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"human-epinions.gl.at.ply.gg"; depth:27; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414072/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 75%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/xe1o"; depth:5; nocase; http.host; content:"20.74.209.192"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414073/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414073; rev:1;) alert tcp $HOME_NET any -> [37.107.11.247] 443 (msg:"ThreatFox QakBot botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414069/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414069; rev:1;) alert tcp $HOME_NET any -> [37.27.87.24] 8888 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414070/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414070; rev:1;) alert tcp $HOME_NET any -> [185.100.157.145] 1515 (msg:"ThreatFox NjRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414068/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414068; rev:1;) alert tcp $HOME_NET any -> [20.173.41.208] 8888 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414067/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414067; rev:1;) alert tcp $HOME_NET any -> [188.49.58.85] 995 (msg:"ThreatFox QakBot botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414066/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414066; rev:1;) alert tcp $HOME_NET any -> [13.48.26.102] 4369 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414065/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414065; rev:1;) alert tcp $HOME_NET any -> [13.248.209.49] 443 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414064/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414064; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.masvt.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414058/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414058; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.cikwp.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414059/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414059; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.cikwp.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414060/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414060; rev:1;) alert tcp $HOME_NET any -> [84.154.180.143] 82 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414057/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414057; rev:1;) alert tcp $HOME_NET any -> [3.96.151.21] 788 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414055/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414055; rev:1;) alert tcp $HOME_NET any -> [35.180.211.187] 5984 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414056/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414056; rev:1;) alert tcp $HOME_NET any -> [52.231.109.121] 443 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414054/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414054; rev:1;) alert tcp $HOME_NET any -> [138.199.162.81] 2086 (msg:"ThreatFox Quasar RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414053/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414053; rev:1;) alert tcp $HOME_NET any -> [23.94.126.207] 1999 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414052/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414052; rev:1;) alert tcp $HOME_NET any -> [146.70.113.148] 4444 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414051/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414051; rev:1;) alert tcp $HOME_NET any -> [185.38.142.181] 443 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414050/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414050; rev:1;) alert tcp $HOME_NET any -> [196.251.118.14] 2404 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414048/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414048; rev:1;) alert tcp $HOME_NET any -> [193.23.3.29] 1570 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414049/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414049; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.masvt.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414047/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414047; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.lalml.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414027/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414027; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.lalml.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414026/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414026; rev:1;) alert tcp $HOME_NET any -> [198.135.51.176] 49950 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414046/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414046; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"xu3.201008281.xyz"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414045/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414045; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"xu3.201008281.xyz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414044/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414044; rev:1;) alert tcp $HOME_NET any -> [47.92.26.48] 8088 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414043/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414043; rev:1;) alert tcp $HOME_NET any -> [185.196.9.225] 6606 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414041/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414041; rev:1;) alert tcp $HOME_NET any -> [185.196.9.225] 7707 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414042/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414042; rev:1;) alert tcp $HOME_NET any -> [185.196.9.225] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414040/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414040; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"category-tar.gl.at.ply.gg"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414039/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414039; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"austin99.duckdns.org"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414037/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414037; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"heksaa3030.redirectme.net"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414038/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414038; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"although-evans.gl.at.ply.gg"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414036/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"crimson-sun-3ac5.foxiproxi.workers.dev"; depth:38; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414035/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414035; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"154.26.208.209"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414034/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"softpafthway.cyou"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414033/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414033; rev:1;) alert tcp $HOME_NET any -> [54.184.8.206] 593 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414031/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414031; rev:1;) alert tcp $HOME_NET any -> [176.82.171.71] 6001 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414032/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414032; rev:1;) alert tcp $HOME_NET any -> [75.119.139.188] 92 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414030/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91414030; rev:1;) alert tcp $HOME_NET any -> [89.117.17.182] 6606 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414029/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414029; rev:1;) alert tcp $HOME_NET any -> [176.65.138.184] 3939 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414028/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414028; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.nolzm.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1414024/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414024; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.nolzm.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1414025/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414025; rev:1;) alert tcp $HOME_NET any -> [79.107.152.170] 995 (msg:"ThreatFox QakBot botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414021/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414021; rev:1;) alert tcp $HOME_NET any -> [81.19.140.168] 8080 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414019/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414019; rev:1;) alert tcp $HOME_NET any -> [39.107.243.6] 8443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414020/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414020; rev:1;) alert tcp $HOME_NET any -> [3.81.133.133] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414017/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414017; rev:1;) alert tcp $HOME_NET any -> [20.236.253.207] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414018/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414018; rev:1;) alert tcp $HOME_NET any -> [95.169.180.41] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414016/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414016; rev:1;) alert tcp $HOME_NET any -> [128.140.34.177] 34956 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414014/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414014; rev:1;) alert tcp $HOME_NET any -> [178.238.105.57] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414015/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414015; rev:1;) alert tcp $HOME_NET any -> [54.224.124.160] 443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414013/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414013; rev:1;) alert tcp $HOME_NET any -> [191.113.109.14] 8080 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414012/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414012; rev:1;) alert tcp $HOME_NET any -> [66.194.172.174] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414010/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414010; rev:1;) alert tcp $HOME_NET any -> [34.136.174.197] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414011/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414011; rev:1;) alert tcp $HOME_NET any -> [20.216.218.254] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414009/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414009; rev:1;) alert tcp $HOME_NET any -> [13.61.4.166] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414007/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414007; rev:1;) alert tcp $HOME_NET any -> [184.82.106.56] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414008/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414008; rev:1;) alert tcp $HOME_NET any -> [172.232.235.202] 443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414005/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414005; rev:1;) alert tcp $HOME_NET any -> [5.253.41.69] 60000 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414006/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414006; rev:1;) alert tcp $HOME_NET any -> [172.232.235.202] 55487 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414004/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414004; rev:1;) alert tcp $HOME_NET any -> [172.232.235.202] 6513 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414002/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414002; rev:1;) alert tcp $HOME_NET any -> [172.232.235.202] 50102 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414003/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414003; rev:1;) alert tcp $HOME_NET any -> [172.232.235.202] 2095 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414001/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414001; rev:1;) alert tcp $HOME_NET any -> [154.26.208.209] 8089 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414000/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414000; rev:1;) alert tcp $HOME_NET any -> [134.122.128.91] 1234 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413998/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413998; rev:1;) alert tcp $HOME_NET any -> [154.26.208.209] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413999/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413999; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"detailerqusit.help"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413982/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413982; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"mintysoary.help"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413983/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413983; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"hopefulpatkh.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413984/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413984; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"intentionalklife.top"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413985/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413985; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"joyfuljourneky.top"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413986/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413986; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"kindplacesk.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413987/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413987; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"liemitlgessdream.top"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413988/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413988; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"minedfrulgrowth.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413989/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413989; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"noureeishedsoul.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413990/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413990; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"opetnheearts.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413991/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413991; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"diggyacito.click"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413992/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413992; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"dirtytram.click"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413993/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413993; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"potcryscanj.shop"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413995/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413995; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"medicalprocce.shop"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413994/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413994; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"silingwhip.shop"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413996/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413996; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"jookerkslxsafkr.xyz"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413981/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413981; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"preyechostun.pro"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413974/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413974; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"kinguserpart.pro"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413972/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413972; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"painroomarch.pro"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413973/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413973; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"fearrealmean.pro"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413971/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413971; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"campskipleak.pro"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413970/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413970; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"smsfastersend.com"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413967/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413967; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"americanexpressloginus.com"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413968/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413968; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"suomi-app.net"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413966/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413966; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"mitgpssms.com"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413965/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413965; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.php"; depth:6; nocase; http.host; content:"mgkwjihehqcknbp.top"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413963/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413963; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"mgkwjihehqcknbp.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413964/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413964; rev:1;) alert tcp $HOME_NET any -> [160.22.160.31] 56999 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413961/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91413961; rev:1;) alert tcp $HOME_NET any -> [193.143.1.42] 60255 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413962/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413962; rev:1;) alert tcp $HOME_NET any -> [37.221.67.207] 1111 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413960/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91413960; rev:1;) alert tcp $HOME_NET any -> [37.221.67.207] 45 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413959/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91413959; rev:1;) alert tcp $HOME_NET any -> [37.221.67.207] 6969 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413958/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_17; classtype:trojan-activity; sid:91413958; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"kjhgfdsaasdfgh.myvnc.com"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413937/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413937; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"stoya.no-ip.biz"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413938/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413938; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"dbam.dyndns.org"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413939/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413939; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"yesmoke.no-ip.org"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413940/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413940; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"surrogates7.no-ip.org"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413941/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413941; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"borcanoo.zapto.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413942/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413942; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"elamr.no-ip.org"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413943/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413943; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"booooooty.duckdns.org"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413944/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413944; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"liberiumtop-59052.portmap.host"; depth:30; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413945/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413945; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"jokeersbox-21442.portmap.host"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413946/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413946; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"issues-sarah.gl.at.ply.gg"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413947/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413947; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"left-councils.gl.at.ply.gg"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413948/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413948; rev:1;) alert tcp $HOME_NET any -> [212.15.49.100] 1212 (msg:"ThreatFox SpyNote botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413949/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413949; rev:1;) alert tcp $HOME_NET any -> [158.69.12.143] 5555 (msg:"ThreatFox SpyNote botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413950/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413950; rev:1;) alert tcp $HOME_NET any -> [147.189.171.248] 7771 (msg:"ThreatFox SpyNote botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413951/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413951; rev:1;) alert tcp $HOME_NET any -> [184.174.97.115] 5002 (msg:"ThreatFox SpyNote botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413952/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413952; rev:1;) alert tcp $HOME_NET any -> [154.16.93.177] 3368 (msg:"ThreatFox NetWire RC botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413935/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413935; rev:1;) alert tcp $HOME_NET any -> [154.16.93.177] 3365 (msg:"ThreatFox NetWire RC botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413936/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413936; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"yxrqxlvregipunw.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413932/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413932; rev:1;) alert tcp $HOME_NET any -> [96.62.214.212] 3778 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413933/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413933; rev:1;) alert tcp $HOME_NET any -> [195.178.110.224] 8888 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413934/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413934; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"scanpaq.com"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413929/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.php"; depth:6; nocase; http.host; content:"yxrqxlvregipunw.top"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413931/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/js.php"; depth:7; nocase; http.host; content:"scanpaq.com"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413930/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6t5t.js"; depth:8; nocase; http.host; content:"scanpaq.com"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413928/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/rfp1ykrwym1odxc.exe"; depth:24; nocase; http.host; content:"154.216.20.22"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413897/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413897; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/tielklvkfumqufa.exe"; depth:24; nocase; http.host; content:"87.120.84.38"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413898/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413898; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/zo7yvjlvmdji9aj.exe"; depth:24; nocase; http.host; content:"87.120.84.39"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413899/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413899; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/zf3dxapdnla4lnl.exe"; depth:24; nocase; http.host; content:"87.120.84.38"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413900/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413900; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/di5nuab6dcw7eov.exe"; depth:24; nocase; http.host; content:"87.120.84.39"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413901/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413901; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/fwacz73tnxebaj2.exe"; depth:24; nocase; http.host; content:"87.120.84.38"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413902/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413902; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/ok7yvjlvmdji9ajz.exe"; depth:25; nocase; http.host; content:"87.120.84.38"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413903/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413903; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/nfef2debp7q52qq.exe"; depth:24; nocase; http.host; content:"87.120.84.39"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413904/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413904; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/iwqopplghcvzxmy.exe"; depth:24; nocase; http.host; content:"87.120.84.39"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413905/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413905; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/h363bpkqz0mdvd7.exe"; depth:24; nocase; http.host; content:"66.63.187.123"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413906/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413906; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/blhbzrtqblg6o1k.exe"; depth:24; nocase; http.host; content:"87.120.84.39"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413907/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413907; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/sr01fduyuje6o2v.exe"; depth:24; nocase; http.host; content:"154.216.20.22"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413908/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413908; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/i3xzep1kscpdmj7.exe"; depth:24; nocase; http.host; content:"87.120.84.39"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413909/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413909; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/en7nq8lm3v7yww0.exe"; depth:24; nocase; http.host; content:"87.120.84.39"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413910/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413910; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/zok7yvjlvmdji9aj.exe"; depth:25; nocase; http.host; content:"87.120.84.38"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413911/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413911; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/u7vqmxbxibxvbxn.exe"; depth:24; nocase; http.host; content:"154.216.19.160"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413912/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413912; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/yvdk2vzluodbu6s.exe"; depth:24; nocase; http.host; content:"154.216.19.160"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413913/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413913; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/f2rps6mhkljoach.exe"; depth:24; nocase; http.host; content:"87.120.84.38"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413914/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413914; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/gsetc3enkk2egl4.exe"; depth:24; nocase; http.host; content:"87.120.84.38"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413915/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413915; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/ttuygt18rb5jzcr.exe"; depth:24; nocase; http.host; content:"87.120.84.38"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413916/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413916; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/uyikxzbgrrplkjh.exe"; depth:24; nocase; http.host; content:"87.120.84.38"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413917/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413917; rev:1;) alert tcp $HOME_NET any -> [35.167.121.116] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413918/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413918; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"13.251.16.150"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413922/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413922; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"cnc.pinklander.com"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413923/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413923; rev:1;) alert tcp $HOME_NET any -> [199.195.252.200] 808 (msg:"ThreatFox Kaiji botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413924/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413924; rev:1;) alert tcp $HOME_NET any -> [185.112.102.12] 3778 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413926/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413926; rev:1;) alert tcp $HOME_NET any -> [196.251.67.134] 13 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413927/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/ettb15lcedjyw3r.exe"; depth:24; nocase; http.host; content:"154.216.19.160"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413895/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413895; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/lwk7fu5kbewfbqc.exe"; depth:24; nocase; http.host; content:"66.63.187.123"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413892/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413892; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/xxdquuorm1vd3an.exe"; depth:24; nocase; http.host; content:"87.120.84.39"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413893/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413893; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/aegtitprcz9bkkq.exe"; depth:24; nocase; http.host; content:"154.216.19.160"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413894/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413894; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/dtglbrsub45qnmm.exe"; depth:24; nocase; http.host; content:"87.120.84.38"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413891/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413891; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"webbased-stub-builder.vercel.app"; depth:32; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413885/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413885; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"radiatntideas.top"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413857/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413857; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/xugzybfe02qd31l.exe"; depth:24; nocase; http.host; content:"154.216.19.160"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413890/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413890; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/txt/um9l61wgoaplfkj.exe"; depth:24; nocase; http.host; content:"154.216.19.160"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413896/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413896; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"lovechat.sbs"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413878/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413878; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"bchainpro.com"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413879/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413879; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"rblcardservice.com"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413880/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413880; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"hdbservicepdl.com"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413881/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413881; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/772a09d8ce7f9f4da9fc0087f1cf84f12aedb2e2cfbf9989.bin"; depth:53; nocase; http.host; content:"ly.ardentlysqueamish.autos"; depth:26; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413882/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413882; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.buqqn.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413883/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413883; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.buqqn.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413884/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413884; rev:1;) alert tcp $HOME_NET any -> [62.60.226.49] 1115 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414023/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91414023; rev:1;) alert tcp $HOME_NET any -> [216.250.252.33] 60309 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1414022/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91414022; rev:1;) alert tcp $HOME_NET any -> [111.180.203.230] 6666 (msg:"ThreatFox ValleyRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413997/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413997; rev:1;) alert tcp $HOME_NET any -> [144.126.223.33] 80 (msg:"ThreatFox MooBot botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413980/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413980; rev:1;) alert tcp $HOME_NET any -> [191.96.207.172] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413979/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413979; rev:1;) alert tcp $HOME_NET any -> [134.122.128.93] 1234 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413978/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413978; rev:1;) alert tcp $HOME_NET any -> [112.126.68.13] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413977/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413977; rev:1;) alert tcp $HOME_NET any -> [45.144.136.13] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413976/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413976; rev:1;) alert tcp $HOME_NET any -> [45.115.236.152] 37232 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413975/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413975; rev:1;) alert tcp $HOME_NET any -> [196.251.71.31] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413969/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_17; classtype:trojan-activity; sid:91413969; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"www.phpmyadmin.timeweb25.ru"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413957/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413957; rev:1;) alert tcp $HOME_NET any -> [23.94.126.207] 2004 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413956/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413956; rev:1;) alert tcp $HOME_NET any -> [196.251.118.49] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413955/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413955; rev:1;) alert tcp $HOME_NET any -> [206.123.152.34] 3191 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413954/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413954; rev:1;) alert tcp $HOME_NET any -> [148.153.82.222] 8081 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413953/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_17; classtype:trojan-activity; sid:91413953; rev:1;) alert tcp $HOME_NET any -> [147.185.221.25] 65218 (msg:"ThreatFox NjRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413925/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413925; rev:1;) alert tcp $HOME_NET any -> [20.40.99.133] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413921/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413921; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"network.dhcpclient.com"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413920/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413920; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"global-bibliographic.gl.at.ply.gg"; depth:33; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413889/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413889; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"h4x000r.duckdns.org"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413888/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413888; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"numbers-insights.gl.at.ply.gg"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413887/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413887; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"dasdv1.service1921.club"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413886/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413886; rev:1;) alert tcp $HOME_NET any -> [64.188.99.4] 8888 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413877/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413877; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 3116 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413876/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413876; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 29016 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413873/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413873; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 29924 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413874/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413874; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 30358 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413875/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413875; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 24220 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413867/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413867; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 25486 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413868/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413868; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 26193 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413869/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413869; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 27506 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413870/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413870; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 28015 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413871/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413871; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 28911 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413872/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413872; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 23820 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413866/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413866; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 17603 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413864/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413864; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 18244 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413865/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413865; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 10252 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413862/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413862; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 11755 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413863/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413863; rev:1;) alert tcp $HOME_NET any -> [172.111.160.2] 443 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413861/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413861; rev:1;) alert tcp $HOME_NET any -> [159.138.20.150] 60000 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413860/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413860; rev:1;) alert tcp $HOME_NET any -> [13.224.101.73] 443 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413859/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413859; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 75%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/unhr"; depth:5; nocase; http.host; content:"20.74.209.192"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413858/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413858; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.qoqsn.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413855/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413855; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.qoqsn.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413856/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413856; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.goccb.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413853/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413853; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.goccb.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413854/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413854; rev:1;) alert tcp $HOME_NET any -> [45.94.31.85] 8080 (msg:"ThreatFox ERMAC botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413852/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413852; rev:1;) alert tcp $HOME_NET any -> [13.251.129.9] 2079 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413851/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413851; rev:1;) alert tcp $HOME_NET any -> [13.40.37.82] 21 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413850/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413850; rev:1;) alert tcp $HOME_NET any -> [103.68.251.174] 4433 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413848/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413848; rev:1;) alert tcp $HOME_NET any -> [82.153.79.9] 443 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413849/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413849; rev:1;) alert tcp $HOME_NET any -> [185.49.126.166] 7707 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413847/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413847; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.zibzr.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413843/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413843; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.zibzr.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413844/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413844; rev:1;) alert tcp $HOME_NET any -> [20.40.99.133] 8080 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413846/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413846; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; nocase; http.host; content:"59.95.95.87"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413845/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413845; rev:1;) alert tcp $HOME_NET any -> [92.118.112.200] 443 (msg:"ThreatFox DanaBot botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413842/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413842; rev:1;) alert tcp $HOME_NET any -> [92.118.112.199] 443 (msg:"ThreatFox DanaBot botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413841/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413841; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.fimdp.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413838/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413838; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.fimdp.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413839/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413839; rev:1;) alert tcp $HOME_NET any -> [45.93.20.15] 15666 (msg:"ThreatFox Meduza Stealer botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413840/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413840; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/art.php"; depth:8; nocase; http.host; content:"swiftvantage.online"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413837/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413837; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.qyfmx.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413834/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.qyfmx.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413835/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413835; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"healthyhabixts.tech"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413836/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413836; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.powqg.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413826/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/guajira.mp3"; depth:12; nocase; http.host; content:"u1.giddinessrebirth.shop"; depth:24; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413827/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413827; rev:1;) alert tcp $HOME_NET any -> [144.172.73.45] 9931 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413829/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413829; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"u1.giddinessrebirth.shop"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413828/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413828; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.hivrv.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413832/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413832; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.hivrv.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413833/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413833; rev:1;) alert tcp $HOME_NET any -> [88.244.209.174] 3333 (msg:"ThreatFox NjRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413831/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pythonlinuxuploads.php"; depth:23; nocase; http.host; content:"136601cm.shnyash.ru"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413830/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413830; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.powqg.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413825/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413825; rev:1;) alert tcp $HOME_NET any -> [3.70.11.235] 7723 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413824/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413824; rev:1;) alert tcp $HOME_NET any -> [109.248.162.19] 443 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413823/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413823; rev:1;) alert tcp $HOME_NET any -> [154.30.3.134] 31415 (msg:"ThreatFox Quasar RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413822/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413822; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"b.gewrye.shop"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413820/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413820; rev:1;) alert tcp $HOME_NET any -> [172.111.244.104] 8347 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413821/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413821; rev:1;) alert tcp $HOME_NET any -> [45.11.92.73] 56999 (msg:"ThreatFox MooBot botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413819/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.mojtf.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413816/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413816; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.reqpn.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413817/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.reqpn.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413818/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413818; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.mojtf.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413815/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413815; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"digitalservice.ddnsguru.com"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413814/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"www.iq-insitute.org"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413813/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"37.60.238.252"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413812/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"radiatntideas.top"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413811/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413811; rev:1;) alert tcp $HOME_NET any -> [194.87.68.243] 10134 (msg:"ThreatFox Orcus RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413810/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413810; rev:1;) alert tcp $HOME_NET any -> [18.134.95.174] 3306 (msg:"ThreatFox BlackShades botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413809/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413809; rev:1;) alert tcp $HOME_NET any -> [64.95.11.106] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413805/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413805; rev:1;) alert tcp $HOME_NET any -> [174.138.78.76] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413806/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413806; rev:1;) alert tcp $HOME_NET any -> [45.9.148.62] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413807/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413807; rev:1;) alert tcp $HOME_NET any -> [66.228.32.147] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413808/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/_defaultwindows.php"; depth:20; nocase; http.host; content:"a0768683.xsph.ru"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413804/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413804; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.tusmh.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413802/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.tusmh.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413803/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.gyhxr.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413801/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413801; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.gyhxr.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413800/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413800; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.revrb.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413798/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.revrb.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413799/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.zuzcq.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413797/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413797; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"ads.green-pickle-jo.shop"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413788/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413788; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.zuzcq.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413793/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413793; rev:1;) alert tcp $HOME_NET any -> [92.255.85.36] 15847 (msg:"ThreatFox SectopRAT botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413795/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413795; rev:1;) alert tcp $HOME_NET any -> [92.255.85.36] 9000 (msg:"ThreatFox SectopRAT botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413796/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413796; rev:1;) alert tcp $HOME_NET any -> [216.122.166.17] 8237 (msg:"ThreatFox Antidot botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413794/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413794; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"festalferalweek.online"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413792/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413792; rev:1;) alert tcp $HOME_NET any -> [91.212.166.54] 443 (msg:"ThreatFox AMOS botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413791/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/macshare.php"; depth:13; nocase; http.host; content:"sqairs.com"; depth:10; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413790/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413790; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sqairs.com"; depth:10; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413789/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 75%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"jookerkslxsafkr.xyz"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413787/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413787; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.kaqpw.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413783/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.kaqpw.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413786/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413786; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"peactefulpath.top"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413785/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"peactefulpath.top"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413784/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"you-insk-bad.pages.dev"; depth:22; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413368/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"fresh-orange-juice.pages.dev"; depth:28; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413370/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413370; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ads.green-pickle-jo.shop"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413372/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413372; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"fresh-orange-juice.pages.dev"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413369/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/1.m4a"; depth:6; nocase; http.host; content:"ads.green-pickle-jo.shop"; depth:24; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413371/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413371; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"intentionalklife.top"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413353/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413353; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"hopefulpatkh.top"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413354/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413354; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"you-insk-bad.pages.dev"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413367/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.piqcz.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413352/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413352; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.piqcz.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413351/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413351; rev:1;) alert tcp $HOME_NET any -> [119.8.38.62] 7777 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413782/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413782; rev:1;) alert tcp $HOME_NET any -> [47.129.34.49] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413781/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"abnormasik.click"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413780/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"ickyseeky.shop"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413779/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413779; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"tenpp10sb.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413778/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413778; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"thrtjj13sr.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413775/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413775; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"fiveuu5pn.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413776/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413776; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"frtnjj14sr.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413777/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413777; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"thrtuu13pn.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413774/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413774; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sixzx6vs.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413772/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413772; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"twozx2vs.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413773/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413773; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"forbz4sr.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413744/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413744; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"onev1sr.top"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413745/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413745; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"twov2sr.top"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413746/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413746; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"onexv1pn.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413747/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413747; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"forbz4pn.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413748/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413748; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"onexv1vs.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413749/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413749; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"twoxv2pt.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413750/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413750; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sixxv6pt.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413751/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413751; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"onexv1pt.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413752/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413752; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"twoxv2sr.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413753/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413753; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"threxv3sr.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413754/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413754; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"fivexv5sr.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413755/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413755; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"onexv1sr.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413756/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413756; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sixxv6sr.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413757/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413757; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"onexc1pn.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413758/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413758; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"threq3pn.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413759/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413759; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sixxc6pn.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413760/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413760; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"twoxc2pn.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413761/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413761; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"fivexx5pn.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413762/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413762; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sixxc6pt.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413763/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413763; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"twoxc2pt.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413764/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413764; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sixxc6vt.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413765/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413765; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"twoxc2vt.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413766/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413766; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"fivexx5vt.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413767/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413767; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"onexc1vt.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413768/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413768; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"threxx3vt.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413769/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413769; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"neizx9vs.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413770/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413770; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"onezc1vs.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413771/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413771; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"onev1pt.top"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413743/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413743; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"forz4pt.top"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413742/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413742; rev:1;) alert tcp $HOME_NET any -> [47.239.165.225] 8443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413741/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413741; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"onev1sb.top"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413740/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413740; rev:1;) alert tcp $HOME_NET any -> [20.0.106.6] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413739/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413739; rev:1;) alert tcp $HOME_NET any -> [184.77.150.121] 1604 (msg:"ThreatFox DarkComet botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413730/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413730; rev:1;) alert tcp $HOME_NET any -> [213.190.57.17] 4411 (msg:"ThreatFox DarkComet botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413731/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413731; rev:1;) alert tcp $HOME_NET any -> [92.73.139.121] 3460 (msg:"ThreatFox DarkComet botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413732/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413732; rev:1;) alert tcp $HOME_NET any -> [130.193.142.41] 1604 (msg:"ThreatFox DarkComet botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413733/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413733; rev:1;) alert tcp $HOME_NET any -> [193.242.166.48] 1605 (msg:"ThreatFox DarkComet botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413734/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413734; rev:1;) alert tcp $HOME_NET any -> [109.236.61.60] 1604 (msg:"ThreatFox DarkComet botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413735/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413735; rev:1;) alert tcp $HOME_NET any -> [81.220.71.93] 1604 (msg:"ThreatFox DarkComet botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413736/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413736; rev:1;) alert tcp $HOME_NET any -> [68.144.181.57] 999 (msg:"ThreatFox DarkComet botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413737/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413737; rev:1;) alert tcp $HOME_NET any -> [69.243.133.201] 100 (msg:"ThreatFox DarkComet botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413738/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413738; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"winrarsfx.zapto.org"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413701/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413701; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"edog778.no-ip.biz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413702/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413702; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"uoku.sytes.net"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413703/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413703; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"r-wlany.no-ip.org"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413704/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413704; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"turkuhacker70.no-ip.org"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413705/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413705; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"357hftphhm.no-ip.org"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413706/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413706; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"serverbudau.no-ip.org"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413707/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413707; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"fingers.no-ip.biz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413708/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413708; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"williamm.no-ip.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413709/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413709; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"forum.3utilities.com"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413710/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413710; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"googler.3utilities.com"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413711/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413711; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"oox.no-ip.org"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413712/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413712; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"hoszelaar.no-ip.org"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413713/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413713; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"leethost.no-ip.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413714/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413714; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cgdutchn00bz.no-ip.biz"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413715/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413715; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"etclan.no-ip.org"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413716/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413716; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"hackman.no-ip.org"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413717/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413717; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"r3c0n.no-ip.org"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413718/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413718; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"omaromar.zapto.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413719/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413719; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"gniewkowiec0359.zapto.org"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413720/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413720; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"mrlokoniqq.no-ip.org"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413721/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413721; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"misteryou79.no-ip.org"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413722/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413722; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"face005.zapto.org"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413723/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413723; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"lololol.hopto.org"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413724/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413724; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"arpej.duckdns.org"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413725/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413725; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"welljacker.no-ip.org"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413726/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413726; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"foxiland.no-ip.info"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413727/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413727; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"bsserver1337.no-ip.biz"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413728/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413728; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"winrarsfx.linkpc.net"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413729/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413729; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cruee.no-ip.biz"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413671/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413671; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sbregar.zapto.org"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413672/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413672; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"trinydarkcomet.no-ip.biz"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413673/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413673; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"jacker.no-ip.info"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413674/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413674; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"retards.zapto.org"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413675/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413675; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sahli.no-ip.org"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413676/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413676; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"meexonline.no-ip.org"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413677/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413677; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"norgledys.no-ip.org"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413678/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413678; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"socold.no-ip.org"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413679/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413679; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ace369258147.no-ip.biz"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413680/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413680; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"iamusinganoip.no-ip.org"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413681/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413681; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"pointblankv1.duckdns.org"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413682/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413682; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"xmgx.no-ip.biz"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413683/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413683; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"blackzx.no-ip.org"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413684/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413684; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"r3xr3g1s.no-ip.info"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413685/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413685; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"welljack.no-ip.biz"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413686/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413686; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"arsene.no-ip.org"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413687/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413687; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ygo.no-ip.info"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413688/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413688; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"w0xx-24.no-ip.biz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413689/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413689; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sonykuccio.no-ip.biz"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413690/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413690; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"leethackers.no-ip.biz"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413691/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413691; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cybertechnologyinc.no-ip.biz"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413692/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413692; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"glhacker.zapto.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413693/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413693; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"tommyhf.no-ip.biz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413694/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413694; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"omerexpert.no-ip.biz"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413695/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413695; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"inworld.vip.sh"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413696/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413696; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sprk.no-ip.biz"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413697/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413697; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"destructoid.no-ip.biz"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413698/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413698; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ka8evdei.no-ip.info"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413699/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413699; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"zackzm.zapto.org"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413700/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413700; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"tylerb0ss.no-ip.org"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413650/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413650; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"zooma151.no-ip.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413651/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413651; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"raul1115.no-ip.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413652/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413652; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sourcegen.no-ip.biz"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413653/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413653; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ghoststarcraft.no-ip.info"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413654/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413654; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"75as4d53a1sd.zapto.org"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413655/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413655; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cerebrius.zapto.org"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413656/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413656; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"blackzx.no-ip.biz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413657/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413657; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"matt.no-ip.biz"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413658/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413658; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"moehome.dyndns.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413659/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413659; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"mylovely.zapto.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413660/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413660; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"daniele2.no-ip.info"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413661/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413661; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"asm296.no-ip.biz"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413662/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413662; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"garcon.no-ip.biz"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413663/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413663; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"adsa123.no-ip.info"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413664/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413664; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cl0m3nt.no-ip.biz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413665/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413665; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"taping.duckdns.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413666/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413666; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"romhacker.no-ip.biz"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413667/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413667; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"darkserver.no-ip.info"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413668/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413668; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"rabun95.no-ip.biz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413669/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413669; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"kromoz23.no-ip.biz"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413670/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413670; rev:1;) alert tcp $HOME_NET any -> [195.189.238.68] 81 (msg:"ThreatFox CyberGate botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413644/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413644; rev:1;) alert tcp $HOME_NET any -> [178.49.37.59] 6112 (msg:"ThreatFox CyberGate botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413645/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413645; rev:1;) alert tcp $HOME_NET any -> [117.204.52.77] 84 (msg:"ThreatFox CyberGate botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413646/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413646; rev:1;) alert tcp $HOME_NET any -> [5.71.212.194] 81 (msg:"ThreatFox CyberGate botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413647/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413647; rev:1;) alert tcp $HOME_NET any -> [185.224.0.239] 666 (msg:"ThreatFox Bashlite botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413648/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413648; rev:1;) alert tcp $HOME_NET any -> [82.153.138.142] 12345 (msg:"ThreatFox Bashlite botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413649/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413649; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ifp2011.no-ip.info"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413629/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413629; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"retchard.no-ip.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413630/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413630; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ownedyou1125.no-ip.org"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413631/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413631; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"h2x2.myftp.biz"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413632/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413632; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"metus1337.zapto.org"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413633/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413633; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"flapdrolyordi.zapto.org"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413634/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413634; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"volemal.zapto.org"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413635/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413635; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"random1p.no-ip.biz"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413636/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413636; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"system30.servegame.com"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413637/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413637; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"testgivi.no-ip.biz"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413638/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413638; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"showonnnnn.no-ip.info"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413639/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413639; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"s3ds3ood2010.no-ip.biz"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413640/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413640; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"funtoushe-77.zapto.org"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413641/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413641; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"adminftp.ftpaccess.cc"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413642/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413642; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"maier-maxi.zapto.org"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413643/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413643; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"vivahopy1.sytes.net"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413599/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413599; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"stiuvert.no-ip.biz"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413600/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413600; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"hmssal7ob.no-ip.biz"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413601/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413601; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"wardy94.no-ip.biz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413602/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413602; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"popodepepe.zapto.org"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413603/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413603; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"hackguner.zapto.org"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413604/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413604; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"seki111.no-ip.info"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413605/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413605; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"javaupdater.servehttp.com"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413606/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413606; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ewfewf.zapto.org"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413607/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413607; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"updater200.no-ip.biz"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413608/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413608; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"hackernabli.no-ip.org"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413609/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413609; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"newhome.homelinux.com"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413610/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413610; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sagegc.zapto.org"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413611/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413611; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"shitheads.no-ip.com"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413612/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413612; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ugandascape.no-ip.biz"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413613/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413613; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"dainius1122.no-ip.biz"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413614/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413614; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"anmelden1231.zapto.org"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413615/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413615; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"deniszhack.no-ip.org"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413616/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413616; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"aravind11301.no-ip.info"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413617/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413617; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cfyserver.sytes.net"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413618/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413618; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"karizma05.no-ip.biz"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413619/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413619; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"jillnet.hopto.org"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413620/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413620; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"xspas.no-ip.biz"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413621/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413621; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"myserverfree.no-ip.org"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413622/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413622; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"zagkorat.no-ip.biz"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413623/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413623; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"securex812.no-ip.info"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413624/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413624; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"glorty1.no-ip.biz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413625/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413625; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"xxben240xx.no-ip.biz"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413626/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413626; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"thanhhoai.no-ip.org"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413627/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413627; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"smel45454.no-ip.biz"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413628/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413628; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"layla.no-ip.biz"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413568/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413568; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"fickenman.no-ip.biz"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413569/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413569; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"genelev.sytes.net"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413570/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413570; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"waitforme.no-ip.org"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413571/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413571; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"blacktiger05.no-ip.biz"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413572/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413572; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"504487l.zapto.org"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413573/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413573; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"xtreempje.no-ip.biz"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413574/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413574; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"samir.servehalflife.com"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413575/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413575; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"knightrider1.no-ip.org"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413576/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413576; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cairneyss.no-ip.biz"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413577/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413577; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"shanison.no-ip.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413578/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413578; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cyber123.zapto.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413579/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413579; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"h3nry.no-ip.biz"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413580/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413580; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"fhlogs1.no-ip.biz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413581/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413581; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"hackring-king.no-ip.info"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413582/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413582; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"paxromana.no-ip.org"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413583/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413583; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"bara1994.zapto.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413584/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413584; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"indigo4real34.no-ip.biz"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413585/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413585; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"yabouheli.no-ip.biz"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413586/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413586; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"oramkoburamako2.no-ip.biz"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413587/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413587; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ivanamaa.no-ip.biz"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413588/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413588; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"darkhaked1234.zapto.org"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413589/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413589; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"remotehokben.no-ip.org"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413590/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413590; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"malthegreat.zapto.org"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413591/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413591; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"m0eslem.no-ip.biz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413592/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413592; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"icqservice.serveirc.com"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413593/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413593; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cyberga4teh5cking.no-ip.org"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413594/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413594; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cooperr.no-ip.biz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413595/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413595; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"loto.zapto.org"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413596/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413596; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"naconjo.no-ip.biz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413597/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413597; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"blackwalllie.no-ip.info"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413598/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413598; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"baranreis123.ddns.net"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413551/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413551; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"fbkeys.myftp.org"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413552/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413552; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"hackbertthebrain.no-ip.biz"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413553/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413553; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"heker47.sytes.net"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413554/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413554; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"bra1.no-ip.info"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413555/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413555; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"nour1003.zapto.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413556/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413556; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"lalelulalei.no-ip.org"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413557/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413557; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"itsthetruth.no-ip.biz"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413558/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413558; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"robdark.dyndns.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413559/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413559; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"slaverat.no-ip.biz"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413560/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413560; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"greeting.zapto.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413561/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413561; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"goodconnection.no-ip.biz"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413562/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413562; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"azooze96.no-ip.biz"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413563/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413563; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"aidengz.no-ip.biz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413564/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413564; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"total-free.no-ip.info"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413565/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413565; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"crush31.no-ip.info"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413566/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413566; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"talha.no-ip.info"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413567/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413567; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eqljmjryixwlxpguliyp16"; depth:23; nocase; http.host; content:"home.thrtjj13sr.top"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413545/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413545; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ntrmovgoaovbjpksulkp13"; depth:23; nocase; http.host; content:"home.fortth14ht.top"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413546/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413546; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pbeokzppuoamimahvrmg11"; depth:23; nocase; http.host; content:"home.elvnpp11sb.top"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413547/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413547; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ulvjakqlxazlgwxqjbuu04"; depth:23; nocase; http.host; content:"home.elvnuuu11pn.top"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413548/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413548; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ziudfupkeorigmpcoxua1738611128"; depth:31; nocase; http.host; content:"home.elvnhh11pn.top"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413549/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413549; rev:1;) alert tcp $HOME_NET any -> [158.101.117.24] 4782 (msg:"ThreatFox Nanocore RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413550/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413550; rev:1;) alert tcp $HOME_NET any -> [95.27.4.238] 28015 (msg:"ThreatFox NjRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413541/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413541; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kqeaovfurhdhtcpfrfme15"; depth:23; nocase; http.host; content:"home.twntjj20sr.top"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413542/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413542; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pekvtmslvrbvfmwtjqva17"; depth:23; nocase; http.host; content:"home.elvnjj1sr.top"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413543/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413543; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/joleplgszibrhlkjbqyx17"; depth:23; nocase; http.host; content:"home.fivepp5sb.top"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413544/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413544; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"updateservice.linkpc.net"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413533/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413533; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"njratcrackbiden.zapto.org"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413534/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413534; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"nj1994.duckdns.org"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413535/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413535; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"updatservice3457.ddns.net"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413536/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413536; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sampop.linkpc.net"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413537/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413537; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"mk.babyisis.com.br"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413538/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413538; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"alahacker.no-ip.org"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413539/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413539; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"chromasvaldo.ddns.net"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413540/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413540; rev:1;) alert tcp $HOME_NET any -> [188.127.225.33] 5637 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413529/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413529; rev:1;) alert tcp $HOME_NET any -> [198.135.50.224] 53648 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413530/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413530; rev:1;) alert tcp $HOME_NET any -> [5.45.67.76] 1212 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413531/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413531; rev:1;) alert tcp $HOME_NET any -> [23.94.82.22] 5890 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413532/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413532; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"benhenry2234.zapto.org"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413517/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413517; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"xbbxzqaw.ddns.net"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413518/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413518; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ugobelube.duckdns.org"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413519/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413519; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"kavemarb99juyet5.duckdns.org"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413520/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413520; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"kavemarb99juyet1.duckdns.org"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413521/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413521; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"kavemarb99juyet3.duckdns.org"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413522/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413522; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"supersoftin.duckdns.org"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413523/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413523; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"kavemarb99juyet4.duckdns.org"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413524/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413524; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"netwin66wow.duckdns.org"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413525/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413525; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"kavemarb99juyet6.duckdns.org"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413526/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413526; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"kavemarb99juyet2.duckdns.org"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413527/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413527; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"naps.is-into-games.com"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413528/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413528; rev:1;) alert tcp $HOME_NET any -> [185.241.208.60] 7000 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413503/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413503; rev:1;) alert tcp $HOME_NET any -> [46.8.194.220] 7771 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413504/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413504; rev:1;) alert tcp $HOME_NET any -> [147.185.221.25] 61522 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413505/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413505; rev:1;) alert tcp $HOME_NET any -> [176.65.134.31] 7000 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413506/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413506; rev:1;) alert tcp $HOME_NET any -> [147.185.221.23] 31659 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413507/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413507; rev:1;) alert tcp $HOME_NET any -> [193.161.193.88] 7000 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413508/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413508; rev:1;) alert tcp $HOME_NET any -> [37.114.39.23] 5555 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413509/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413509; rev:1;) alert tcp $HOME_NET any -> [64.7.198.74] 7000 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413510/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413510; rev:1;) alert tcp $HOME_NET any -> [93.80.32.255] 7000 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413511/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413511; rev:1;) alert tcp $HOME_NET any -> [172.245.20.209] 7000 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413512/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413512; rev:1;) alert tcp $HOME_NET any -> [147.185.221.25] 59366 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413513/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413513; rev:1;) alert tcp $HOME_NET any -> [147.185.221.25] 64820 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413514/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413514; rev:1;) alert tcp $HOME_NET any -> [195.177.94.204] 7000 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413515/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413515; rev:1;) alert tcp $HOME_NET any -> [147.185.221.19] 18254 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413490/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413490; rev:1;) alert tcp $HOME_NET any -> [138.124.58.209] 5555 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413491/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413491; rev:1;) alert tcp $HOME_NET any -> [76.141.203.171] 1194 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413492/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413492; rev:1;) alert tcp $HOME_NET any -> [193.161.193.9] 1194 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413493/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413493; rev:1;) alert tcp $HOME_NET any -> [54.224.176.231] 2632 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413494/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413494; rev:1;) alert tcp $HOME_NET any -> [88.127.230.152] 49155 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413495/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413495; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 24703 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413496/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413496; rev:1;) alert tcp $HOME_NET any -> [45.88.91.186] 1234 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413497/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413497; rev:1;) alert tcp $HOME_NET any -> [46.146.38.35] 7000 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413498/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413498; rev:1;) alert tcp $HOME_NET any -> [20.193.152.212] 3392 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413499/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413499; rev:1;) alert tcp $HOME_NET any -> [195.177.94.19] 7000 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413500/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413500; rev:1;) alert tcp $HOME_NET any -> [89.31.122.116] 1123 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413501/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413501; rev:1;) alert tcp $HOME_NET any -> [207.32.218.133] 7234 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413502/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413502; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"md-fort.gl.at.ply.gg"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413484/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413484; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"clxp-34730.portmap.host"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413485/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413485; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sddgdsfgeds-43448.portmap.host"; depth:30; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413486/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413486; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sports-lows.gl.at.ply.gg"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413487/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413487; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"choose-surgeons.gl.at.ply.gg"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413488/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413488; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"nowayjose-61162.portmap.host"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413489/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413489; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"features-exclude.gl.at.ply.gg"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413454/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413454; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"data-save.gl.at.ply.gg"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413455/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413455; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"trust-sri.gl.at.ply.gg"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413456/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413456; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"changes-collection.gl.at.ply.gg"; depth:31; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413457/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413457; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"papers-legendary.gl.at.ply.gg"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413458/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413458; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"quote-symposium.gl.at.ply.gg"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413459/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413459; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"pinkippp.com"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413460/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413460; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"mrn0name-40574.portmap.host"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413461/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413461; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"greater-districts.gl.at.ply.gg"; depth:30; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413462/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413462; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"dsgsdg-45723.portmap.host"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413463/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413463; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"industry-ratings.gl.at.ply.gg"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413464/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413464; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"worldwide-serial.gl.at.ply.gg"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413465/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413465; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"opmans-48990.portmap.host"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413466/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413466; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"plugins-41446.portmap.host"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413467/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413467; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"flash-affordable.gl.at.ply.gg"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413468/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413468; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"journal-maui.gl.at.ply.gg"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413469/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413469; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"mb-them.gl.at.ply.gg"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413470/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413470; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"richard-stuck.gl.at.ply.gg"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413471/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413471; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"beautiful-microphone.gl.at.ply.gg"; depth:33; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413472/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413472; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"wuya-nsw.xyz"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413473/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413473; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"match-os.gl.at.ply.gg"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413474/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413474; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"color-electric.gl.at.ply.gg"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413475/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413475; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"council-boc.gl.at.ply.gg"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413476/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413476; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"child-antibody.gl.at.ply.gg"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413477/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413477; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"discussion-levy.gl.at.ply.gg"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413478/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413478; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"against-generator.gl.at.ply.gg"; depth:30; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413479/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413479; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"name-perception.gl.at.ply.gg"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413480/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413480; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"package-mother.gl.at.ply.gg"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413481/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413481; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"gifts-highs.gl.at.ply.gg"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413482/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413482; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"set-reduces.gl.at.ply.gg"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413483/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413483; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"so-pad.gl.at.ply.gg"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413425/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413425; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"without-affecting.gl.at.ply.gg"; depth:30; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413426/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413426; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"western-bright.gl.at.ply.gg"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413427/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413427; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"heart-colleges.gl.at.ply.gg"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413428/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413428; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"aerd-47210.portmap.host"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413429/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413429; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"have-process.gl.at.ply.gg"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413430/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413430; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"present-seeds.gl.at.ply.gg"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413431/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413431; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"airport-reporter.gl.at.ply.gg"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413432/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413432; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"item-gnu.gl.at.ply.gg"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413433/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413433; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"germany-animal.gl.at.ply.gg"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413434/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413434; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"asked-jd.gl.at.ply.gg"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413435/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413435; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"news-cultures.gl.at.ply.gg"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413436/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413436; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"letter-diamonds.gl.at.ply.gg"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413437/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413437; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"drive-barcelona.gl.at.ply.gg"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413438/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413438; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"el-norm.gl.at.ply.gg"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413439/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413439; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"lead-passage.gl.at.ply.gg"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413440/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413440; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"1305-36961.portmap.host"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413441/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413441; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"conference-std.gl.at.ply.gg"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413442/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413442; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"model-virtually.gl.at.ply.gg"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413443/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413443; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"agentwoo-37720.portmap.host"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413444/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413444; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"agentwoo-62626.portmap.host"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413445/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413445; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"net-enable.gl.at.ply.gg"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413446/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413446; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"support-mere.gl.at.ply.gg"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413447/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413447; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"evilcoder-62402.portmap.host"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413448/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413448; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"skidderhay-32934.portmap.host"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413449/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413449; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"administration-till.gl.at.ply.gg"; depth:32; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413450/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413450; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"battery-mercedes.gl.at.ply.gg"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413451/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413451; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"blog-competitive.gl.at.ply.gg"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413452/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413452; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"distribution-nicaragua.gl.at.ply.gg"; depth:35; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413453/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413453; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot7926380598:aafjrd_ca7fbaplbmehsa_vrzjuzjwdmlws/sendmessage"; depth:62; nocase; http.host; content:"api.telegram.org"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413416/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bot6118451923:aae5b-pwqciyrwostvi2hwoqu2xjltg2ida/sendmessage"; depth:62; nocase; http.host; content:"api.telegram.org"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413417/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413417; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"mar-contest.gl.at.ply.gg"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413418/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413418; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"table-goals.gl.at.ply.gg"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413419/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413419; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sony-duties.gl.at.ply.gg"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413420/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413420; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"benefits-lift.gl.at.ply.gg"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413421/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413421; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ip-definitely.gl.at.ply.gg"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413422/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413422; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"last-would.gl.at.ply.gg"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413423/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413423; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"gedsdg-63727.portmap.host"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413424/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413424; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"vendasdecasas.online"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413407/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413407; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"francoislouis712.duckdns.org"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413408/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413408; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"franclouis882.duckdns.org"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413409/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413409; rev:1;) alert tcp $HOME_NET any -> [149.88.73.200] 8856 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413410/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413410; rev:1;) alert tcp $HOME_NET any -> [176.65.141.235] 4449 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413411/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413411; rev:1;) alert tcp $HOME_NET any -> [176.67.81.11] 443 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413412/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413412; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 56266 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413413/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413413; rev:1;) alert tcp $HOME_NET any -> [147.185.221.26] 1125 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413414/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413414; rev:1;) alert tcp $HOME_NET any -> [27.124.4.150] 51311 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413415/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413415; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"great-wherever.gl.at.ply.gg"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413399/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413399; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"x0jlj7s1ibdosewoq029prs9.duckdns.org"; depth:36; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413400/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413400; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"supersender.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413401/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413401; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"favor.ydns.eu"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413402/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413402; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"seratospm.giize.com"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413403/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413403; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sfsdtgeds-34641.portmap.host"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413404/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413404; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"dgfsdfsdfsdf-60631.portmap.host"; depth:31; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413405/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413405; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"rhgdsg-46696.portmap.host"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413406/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413406; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"douyin.wwvvdouyin.cc"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413398/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413398; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"bigtest.procheckup.com"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413397/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413397; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"2qjhb2csdk7kr.cfc-execute.bj.baidubce.com"; depth:41; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413395/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413395; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"a3dkg2aaaa.westus2.cloudapp.azure.com"; depth:37; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413396/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413396; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"twov2pn.top"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413394/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413394; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"onevd1sr.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413393/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413393; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"threvd3ht.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413392/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413392; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"onevd1ht.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413391/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413391; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"onevd1pt.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413390/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413390; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"twovd2sb.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413389/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413389; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"threvd3sb.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413388/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413388; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"twovd2vt.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413387/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413387; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"threvd3vt.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413386/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413386; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"onevd1vs.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413385/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413385; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"onevd1sb.top"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413384/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413384; rev:1;) alert tcp $HOME_NET any -> [185.102.75.120] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413383/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413383; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"abnormasik.click"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413382/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413382; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ickyseeky.shop"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413381/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413381; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cz34019.tw1.ru"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413380/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413380; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"f1085892.xsph.ru"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413379/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413379; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"f1085679.xsph.ru"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413377/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413377; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"jocer66c.be"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413378/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413378; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"jocer66c.beget.tech"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413376/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413376; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"f1086012.xsph.ru"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413375/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413375; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"fivexc5vs.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413373/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413373; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"fivejj5sr.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413374/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413374; rev:1;) alert tcp $HOME_NET any -> [156.238.230.224] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413366/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413366; rev:1;) alert tcp $HOME_NET any -> [35.180.228.21] 591 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413365/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413365; rev:1;) alert tcp $HOME_NET any -> [150.158.45.167] 14782 (msg:"ThreatFox Quasar RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413364/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413364; rev:1;) alert tcp $HOME_NET any -> [102.117.173.23] 7443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413363/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413363; rev:1;) alert tcp $HOME_NET any -> [185.49.126.166] 2004 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413360/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413360; rev:1;) alert tcp $HOME_NET any -> [149.102.147.106] 1000 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413361/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413361; rev:1;) alert tcp $HOME_NET any -> [162.244.210.40] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413362/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413362; rev:1;) alert tcp $HOME_NET any -> [50.114.115.207] 6606 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413359/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413359; rev:1;) alert tcp $HOME_NET any -> [198.98.48.4] 8888 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413358/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413358; rev:1;) alert tcp $HOME_NET any -> [64.188.99.4] 443 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413357/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413357; rev:1;) alert tcp $HOME_NET any -> [95.163.64.151] 443 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413356/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413356; rev:1;) alert tcp $HOME_NET any -> [80.78.24.94] 8085 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413355/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413355; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"happyhquest.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413080/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413080; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"hopeqfulhearts.top"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413081/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413081; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ideasphark.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413082/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413082; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"inspiqredminds.top"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413083/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413083; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"jololyquest.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413084/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413084; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"joyousqvibes.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413085/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413085; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"kindredqspirits.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413086/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413086; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"lnovewave.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413087/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413087; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"luminousqpath.top"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413088/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413088; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"nexntvision.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413091/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413091; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"gratefulhkeart.top"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413079/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413079; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"graqcefulstep.top"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413078/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413078; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"flouriszhzozne.top"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413076/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413076; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"glowpathy.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413077/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413077; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"elysianfizelds.top"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413073/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413073; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"embracekchange.top"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413074/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413074; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"flourishklife.top"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413075/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413075; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"dreamcrazfters.top"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413071/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413071; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"dreamekrspace.top"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413072/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413072; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cherishzmoments.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413069/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413069; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"creatiyvegroove.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413070/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413070; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"calhmhaven.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413067/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413067; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cherikshedideas.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413068/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413068; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"blisksfulfuture.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413064/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413064; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"blissfzuljourney.top"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413065/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413065; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"brhightfusion.top"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413066/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413066; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ampklevision.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413063/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413063; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"aesthzeticday.top"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413062/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413062; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"mqindfuljourney.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413089/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413089; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"naqturewisdom.top"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413090/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413090; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"oceanbreoeze.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413092/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413092; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"opuqlentnest.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413093/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413093; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"peacqegfulmind.top"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413094/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413094; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"peakaspiroe.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413095/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413095; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"quietreverie.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413096/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413096; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"quiwetwaveso.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413097/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413097; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"radiantnpulse.top"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413098/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413098; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"rgadiantsoul.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413099/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413099; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"riqsingstaro.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413100/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413100; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"segrenewaves.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413101/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413101; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"thwrivenest.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413102/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413102; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"tragnquilgrove.top"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413103/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413103; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"truenorthn.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413104/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413104; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"uniggvgersaljoy.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413105/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413105; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"uyniquequest.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413107/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413107; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"uniwtysphere.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413106/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413106; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"visiwonarypath.top"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413109/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413109; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"vigbragntflow.top"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413108/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413108; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"wzonderfield.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413111/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413111; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"wkanderlustpath.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413110/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413110; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"xpzloreideas.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413112/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413112; rev:1;) alert tcp $HOME_NET any -> [31.171.131.83] 1995 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413040/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413040; rev:1;) alert tcp $HOME_NET any -> [31.59.131.238] 3778 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413061/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413061; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"youzrjoyfulplace.top"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413113/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413113; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"zekalousspirit.top"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413114/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413114; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"zenfylare.top"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413115/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413115; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"zephzyrcloud.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413116/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413116; rev:1;) alert tcp $HOME_NET any -> [117.215.249.82] 60479 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413134/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413134; rev:1;) alert tcp $HOME_NET any -> [59.88.140.173] 38095 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413135/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413135; rev:1;) alert tcp $HOME_NET any -> [61.2.151.2] 53491 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413136/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413136; rev:1;) alert tcp $HOME_NET any -> [102.33.80.182] 55097 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413137/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413137; rev:1;) alert tcp $HOME_NET any -> [103.207.124.49] 46918 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413138/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413138; rev:1;) alert tcp $HOME_NET any -> [60.189.244.224] 57217 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413139/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413139; rev:1;) alert tcp $HOME_NET any -> [103.247.52.197] 54146 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413140/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413140; rev:1;) alert tcp $HOME_NET any -> [119.116.36.65] 40937 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413141/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413141; rev:1;) alert tcp $HOME_NET any -> [103.207.125.52] 52052 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413142/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413142; rev:1;) alert tcp $HOME_NET any -> [45.178.250.90] 10012 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413143/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413143; rev:1;) alert tcp $HOME_NET any -> [190.110.176.83] 34928 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413146/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413146; rev:1;) alert tcp $HOME_NET any -> [110.182.251.206] 48030 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413144/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413144; rev:1;) alert tcp $HOME_NET any -> [59.97.255.106] 41489 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413145/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413145; rev:1;) alert tcp $HOME_NET any -> [185.248.12.129] 53782 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413147/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413147; rev:1;) alert tcp $HOME_NET any -> [178.245.232.95] 41311 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413148/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413148; rev:1;) alert tcp $HOME_NET any -> [222.136.140.83] 42846 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413149/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413149; rev:1;) alert tcp $HOME_NET any -> [27.153.201.216] 52132 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413150/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413150; rev:1;) alert tcp $HOME_NET any -> [175.151.249.161] 57469 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413151/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413151; rev:1;) alert tcp $HOME_NET any -> [103.203.72.139] 54517 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413152/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413152; rev:1;) alert tcp $HOME_NET any -> [103.207.125.5] 60171 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413153/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413153; rev:1;) alert tcp $HOME_NET any -> [221.225.231.34] 51688 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413154/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413154; rev:1;) alert tcp $HOME_NET any -> [45.164.177.102] 11462 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413155/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413155; rev:1;) alert tcp $HOME_NET any -> [115.55.63.117] 56833 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413156/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413156; rev:1;) alert tcp $HOME_NET any -> [59.99.220.103] 58712 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413157/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413157; rev:1;) alert tcp $HOME_NET any -> [211.148.104.167] 52824 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413158/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413158; rev:1;) alert tcp $HOME_NET any -> [103.203.72.227] 35974 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413159/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413159; rev:1;) alert tcp $HOME_NET any -> [103.199.180.156] 41217 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413160/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413160; rev:1;) alert tcp $HOME_NET any -> [120.61.68.97] 50907 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413133/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413133; rev:1;) alert tcp $HOME_NET any -> [117.209.89.62] 57875 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413168/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413168; rev:1;) alert tcp $HOME_NET any -> [42.235.154.113] 52266 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413131/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413131; rev:1;) alert tcp $HOME_NET any -> [59.95.85.40] 54677 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413132/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413132; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"contributioninspection.info"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413126/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413126; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"dreamerfruits.cloud"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413127/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413127; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"aheadrarry.help"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413125/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413125; rev:1;) alert tcp $HOME_NET any -> [103.98.38.150] 54377 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413163/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413163; rev:1;) alert tcp $HOME_NET any -> [117.221.50.51] 41440 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413161/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413161; rev:1;) alert tcp $HOME_NET any -> [103.98.38.173] 56392 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413162/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413162; rev:1;) alert tcp $HOME_NET any -> [192.10.163.76] 41479 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413164/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413164; rev:1;) alert tcp $HOME_NET any -> [45.164.177.171] 11875 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413165/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413165; rev:1;) alert tcp $HOME_NET any -> [219.157.59.83] 42100 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413166/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413166; rev:1;) alert tcp $HOME_NET any -> [1.70.127.236] 50363 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413167/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413167; rev:1;) alert tcp $HOME_NET any -> [103.199.202.192] 34560 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413169/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413169; rev:1;) alert tcp $HOME_NET any -> [223.8.213.139] 59247 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413170/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413170; rev:1;) alert tcp $HOME_NET any -> [175.107.2.115] 39790 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413171/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413171; rev:1;) alert tcp $HOME_NET any -> [117.211.37.103] 47570 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413173/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413173; rev:1;) alert tcp $HOME_NET any -> [202.66.165.57] 37801 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413172/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413172; rev:1;) alert tcp $HOME_NET any -> [117.211.215.108] 54426 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413174/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413174; rev:1;) alert tcp $HOME_NET any -> [191.29.133.216] 39840 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413175/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413175; rev:1;) alert tcp $HOME_NET any -> [182.121.252.121] 56583 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413176/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413176; rev:1;) alert tcp $HOME_NET any -> [103.207.125.55] 59495 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413177/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413177; rev:1;) alert tcp $HOME_NET any -> [117.215.139.182] 51124 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413178/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413178; rev:1;) alert tcp $HOME_NET any -> [172.38.0.225] 57458 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413179/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413179; rev:1;) alert tcp $HOME_NET any -> [115.58.95.45] 36272 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413182/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413182; rev:1;) alert tcp $HOME_NET any -> [119.143.165.164] 49382 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413180/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413180; rev:1;) alert tcp $HOME_NET any -> [61.52.54.208] 47257 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413181/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413181; rev:1;) alert tcp $HOME_NET any -> [42.235.171.56] 58076 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413184/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413184; rev:1;) alert tcp $HOME_NET any -> [115.60.22.211] 6288 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413183/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413183; rev:1;) alert tcp $HOME_NET any -> [103.208.230.41] 42929 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413185/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413185; rev:1;) alert tcp $HOME_NET any -> [115.55.223.75] 46811 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413186/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413186; rev:1;) alert tcp $HOME_NET any -> [121.237.167.31] 52360 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413187/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413187; rev:1;) alert tcp $HOME_NET any -> [125.41.2.112] 57140 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413188/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413188; rev:1;) alert tcp $HOME_NET any -> [59.88.19.247] 47235 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413189/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413189; rev:1;) alert tcp $HOME_NET any -> [103.199.200.252] 50618 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413190/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413190; rev:1;) alert tcp $HOME_NET any -> [117.206.73.192] 60308 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413191/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413191; rev:1;) alert tcp $HOME_NET any -> [103.247.6.98] 48449 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413192/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413192; rev:1;) alert tcp $HOME_NET any -> [42.238.244.143] 48953 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413197/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413197; rev:1;) alert tcp $HOME_NET any -> [42.232.82.206] 32807 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413193/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413193; rev:1;) alert tcp $HOME_NET any -> [117.197.225.182] 45108 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413194/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413194; rev:1;) alert tcp $HOME_NET any -> [45.164.177.197] 10761 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413196/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413196; rev:1;) alert tcp $HOME_NET any -> [109.106.142.43] 63571 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413195/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413195; rev:1;) alert tcp $HOME_NET any -> [182.117.26.62] 32987 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413198/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413198; rev:1;) alert tcp $HOME_NET any -> [45.164.177.162] 11406 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413199/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413199; rev:1;) alert tcp $HOME_NET any -> [125.106.32.67] 33860 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413200/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413200; rev:1;) alert tcp $HOME_NET any -> [59.89.217.42] 59628 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413201/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413201; rev:1;) alert tcp $HOME_NET any -> [117.209.83.6] 35134 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413202/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413202; rev:1;) alert tcp $HOME_NET any -> [125.62.199.32] 47483 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413203/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413203; rev:1;) alert tcp $HOME_NET any -> [183.240.211.144] 36008 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413204/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413204; rev:1;) alert tcp $HOME_NET any -> [123.5.127.175] 49108 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413205/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413205; rev:1;) alert tcp $HOME_NET any -> [27.0.217.195] 40090 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413206/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413206; rev:1;) alert tcp $HOME_NET any -> [102.33.105.87] 52893 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413207/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413207; rev:1;) alert tcp $HOME_NET any -> [59.91.90.29] 51476 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413208/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413208; rev:1;) alert tcp $HOME_NET any -> [112.246.113.161] 33031 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413211/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413211; rev:1;) alert tcp $HOME_NET any -> [59.182.111.124] 39264 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413209/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413209; rev:1;) alert tcp $HOME_NET any -> [117.248.162.244] 32769 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413210/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413210; rev:1;) alert tcp $HOME_NET any -> [59.93.130.217] 56601 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413212/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413212; rev:1;) alert tcp $HOME_NET any -> [123.9.47.122] 50013 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413214/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413214; rev:1;) alert tcp $HOME_NET any -> [117.255.185.229] 53335 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413213/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413213; rev:1;) alert tcp $HOME_NET any -> [115.55.224.32] 52276 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413215/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413215; rev:1;) alert tcp $HOME_NET any -> [117.254.96.59] 42843 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413216/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413216; rev:1;) alert tcp $HOME_NET any -> [175.147.153.77] 56158 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413217/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413217; rev:1;) alert tcp $HOME_NET any -> [117.209.3.106] 60251 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413218/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413218; rev:1;) alert tcp $HOME_NET any -> [182.124.34.64] 59215 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413219/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413219; rev:1;) alert tcp $HOME_NET any -> [117.248.161.189] 60409 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413220/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413220; rev:1;) alert tcp $HOME_NET any -> [59.99.210.136] 37742 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413221/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413221; rev:1;) alert tcp $HOME_NET any -> [211.223.79.89] 54774 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413222/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413222; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.gaxfd.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413223/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413223; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.gaxfd.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413224/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413224; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/guajira.mp3"; depth:12; nocase; http.host; content:"u1.sulkuntie.shop"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413228/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413228; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mdqyztc1mju5mjzi/"; depth:18; nocase; http.host; content:"sunsetvale.xyz"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413232/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413232; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ndi3yjdmytrlzjy3/"; depth:18; nocase; http.host; content:"frozenpeak.xyz"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413233/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413233; rev:1;) alert tcp $HOME_NET any -> [172.179.236.95] 55443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413259/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413259; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/supershell/login/"; depth:18; nocase; http.host; content:"123.58.220.204"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413261/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413261; rev:1;) alert tcp $HOME_NET any -> [45.63.24.192] 7443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413275/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413275; rev:1;) alert tcp $HOME_NET any -> [45.94.31.85] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413276/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413276; rev:1;) alert tcp $HOME_NET any -> [37.60.238.252] 50000 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413277/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413277; rev:1;) alert tcp $HOME_NET any -> [74.249.102.229] 443 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413278/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413278; rev:1;) alert tcp $HOME_NET any -> [3.90.0.40] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413280/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413280; rev:1;) alert tcp $HOME_NET any -> [121.4.218.215] 60000 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413279/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413279; rev:1;) alert tcp $HOME_NET any -> [174.138.57.195] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413281/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413281; rev:1;) alert tcp $HOME_NET any -> [52.57.36.62] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413282/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413282; rev:1;) alert tcp $HOME_NET any -> [52.57.36.62] 443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413283/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413283; rev:1;) alert tcp $HOME_NET any -> [137.184.106.200] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413284/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413284; rev:1;) alert tcp $HOME_NET any -> [47.239.2.3] 82 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413285/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413285; rev:1;) alert tcp $HOME_NET any -> [52.63.165.154] 443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413289/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413289; rev:1;) alert tcp $HOME_NET any -> [13.200.23.247] 443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413286/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413286; rev:1;) alert tcp $HOME_NET any -> [52.28.140.148] 443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413287/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413287; rev:1;) alert tcp $HOME_NET any -> [91.198.220.226] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413288/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413288; rev:1;) alert tcp $HOME_NET any -> [13.39.13.30] 2807 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413290/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413290; rev:1;) alert tcp $HOME_NET any -> [3.142.83.61] 8082 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413291/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413291; rev:1;) alert tcp $HOME_NET any -> [47.101.188.111] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413292/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413292; rev:1;) alert tcp $HOME_NET any -> [82.165.110.142] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413293/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413293; rev:1;) alert tcp $HOME_NET any -> [95.164.55.3] 443 (msg:"ThreatFox DanaBot botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413350/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413350; rev:1;) alert tcp $HOME_NET any -> [89.117.72.46] 8888 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413349/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413349; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 6825 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413348/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413348; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 26791 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413337/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413337; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 27807 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413338/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413338; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 28866 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413339/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413339; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 29024 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413340/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413340; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 29783 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413341/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413341; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 29911 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413342/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413342; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 30699 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413343/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413343; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 31095 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413344/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413344; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 3128 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413345/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413345; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 31307 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413346/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413346; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 31830 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413347/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413347; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 18665 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413329/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413329; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 19432 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413330/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413330; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 19925 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413331/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413331; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 20546 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413332/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413332; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 22368 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413333/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413333; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 23890 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413334/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413334; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 24893 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413335/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413335; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 26034 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413336/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413336; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 13072 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413321/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413321; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 14470 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413322/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413322; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 14974 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413323/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413323; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 15302 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413324/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413324; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 15443 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413325/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413325; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 16192 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413326/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413326; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 16991 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413327/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413327; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 18246 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413328/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413328; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 10000 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413315/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413315; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 10260 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413316/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413316; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 10314 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413317/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413317; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 10480 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413318/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413318; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 11103 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413319/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413319; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 11128 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413320/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413320; rev:1;) alert tcp $HOME_NET any -> [193.26.115.89] 40056 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413314/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413314; rev:1;) alert tcp $HOME_NET any -> [185.195.106.81] 8888 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413313/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413313; rev:1;) alert tcp $HOME_NET any -> [161.35.40.73] 8888 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413312/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413312; rev:1;) alert tcp $HOME_NET any -> [15.236.210.224] 9201 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413311/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413311; rev:1;) alert tcp $HOME_NET any -> [15.235.166.83] 8443 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413310/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_16; classtype:trojan-activity; sid:91413310; rev:1;) alert tcp $HOME_NET any -> [31.171.131.21] 80 (msg:"ThreatFox MooBot botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413309/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413309; rev:1;) alert tcp $HOME_NET any -> [37.235.55.18] 4567 (msg:"ThreatFox NjRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413308/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413308; rev:1;) alert tcp $HOME_NET any -> [147.185.221.25] 63018 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413307/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413307; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"images-hunting.gl.at.ply.gg"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413305/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413305; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"not-warm.gl.at.ply.gg"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413306/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/gu7qawaq"; depth:13; nocase; http.host; content:"pastebin.com"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413304/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413304; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"bz-frnd1.ydns.eu"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413302/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413302; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"systcisd.ddnsking.com"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413303/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413303; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"msiserver.net"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413301/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413301; rev:1;) alert tcp $HOME_NET any -> [57.158.24.35] 443 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413300/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413300; rev:1;) alert tcp $HOME_NET any -> [47.129.248.32] 44158 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413299/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413299; rev:1;) alert tcp $HOME_NET any -> [96.9.124.213] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413298/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413298; rev:1;) alert tcp $HOME_NET any -> [116.204.34.3] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413296/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413296; rev:1;) alert tcp $HOME_NET any -> [37.27.87.24] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413297/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413297; rev:1;) alert tcp $HOME_NET any -> [206.189.56.251] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413294/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413294; rev:1;) alert tcp $HOME_NET any -> [84.238.59.38] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413295/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_16; classtype:trojan-activity; sid:91413295; rev:1;) alert tcp $HOME_NET any -> [54.183.176.59] 30534 (msg:"ThreatFox BianLian botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413273/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413273; rev:1;) alert tcp $HOME_NET any -> [209.97.146.219] 5060 (msg:"ThreatFox BianLian botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413274/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413274; rev:1;) alert tcp $HOME_NET any -> [185.74.222.38] 8080 (msg:"ThreatFox Bashlite botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413272/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413272; rev:1;) alert tcp $HOME_NET any -> [15.197.85.250] 10081 (msg:"ThreatFox Kaiji botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413271/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413271; rev:1;) alert tcp $HOME_NET any -> [20.249.208.141] 443 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413269/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413269; rev:1;) alert tcp $HOME_NET any -> [20.92.165.192] 443 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413270/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413270; rev:1;) alert tcp $HOME_NET any -> [185.49.126.235] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413268/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413268; rev:1;) alert tcp $HOME_NET any -> [185.49.126.235] 2004 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413267/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413267; rev:1;) alert tcp $HOME_NET any -> [5.83.218.75] 443 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413266/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413266; rev:1;) alert tcp $HOME_NET any -> [101.37.150.185] 8443 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413265/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413265; rev:1;) alert tcp $HOME_NET any -> [194.59.31.111] 46167 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413263/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413263; rev:1;) alert tcp $HOME_NET any -> [104.250.169.100] 3191 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413264/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413264; rev:1;) alert tcp $HOME_NET any -> [138.199.162.81] 1863 (msg:"ThreatFox DarkComet botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413262/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eternalimageauthdblinuxwindowsuniversal.php"; depth:44; nocase; http.host; content:"800811cm.nyashk.ru"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413260/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413260; rev:1;) alert tcp $HOME_NET any -> [196.119.150.206] 10000 (msg:"ThreatFox NjRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413258/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413258; rev:1;) alert tcp $HOME_NET any -> [20.199.76.181] 80 (msg:"ThreatFox ERMAC botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413257/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413257; rev:1;) alert tcp $HOME_NET any -> [45.147.176.188] 443 (msg:"ThreatFox PoshC2 botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413256/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413256; rev:1;) alert tcp $HOME_NET any -> [13.245.117.46] 19999 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413253/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413253; rev:1;) alert tcp $HOME_NET any -> [15.228.201.119] 5984 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413254/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413254; rev:1;) alert tcp $HOME_NET any -> [15.228.201.119] 54284 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413255/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413255; rev:1;) alert tcp $HOME_NET any -> [88.17.119.80] 443 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413252/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413252; rev:1;) alert tcp $HOME_NET any -> [5.178.3.137] 4449 (msg:"ThreatFox Venom RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413251/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413251; rev:1;) alert tcp $HOME_NET any -> [186.249.218.242] 443 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413250/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413250; rev:1;) alert tcp $HOME_NET any -> [191.19.117.87] 5000 (msg:"ThreatFox Quasar RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413249/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413249; rev:1;) alert tcp $HOME_NET any -> [73.135.172.24] 7443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413248/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413248; rev:1;) alert tcp $HOME_NET any -> [45.88.186.26] 6606 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413247/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413247; rev:1;) alert tcp $HOME_NET any -> [191.96.207.75] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413245/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413245; rev:1;) alert tcp $HOME_NET any -> [45.88.186.26] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413246/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413246; rev:1;) alert tcp $HOME_NET any -> [23.94.126.207] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413242/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413242; rev:1;) alert tcp $HOME_NET any -> [23.94.126.207] 7707 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413243/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413243; rev:1;) alert tcp $HOME_NET any -> [185.49.126.52] 7707 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413244/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413244; rev:1;) alert tcp $HOME_NET any -> [107.175.48.5] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413240/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413240; rev:1;) alert tcp $HOME_NET any -> [185.49.126.245] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413241/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413241; rev:1;) alert tcp $HOME_NET any -> [45.87.173.96] 2404 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413238/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413238; rev:1;) alert tcp $HOME_NET any -> [212.162.155.84] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413239/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413239; rev:1;) alert tcp $HOME_NET any -> [152.32.253.15] 8888 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413237/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413237; rev:1;) alert tcp $HOME_NET any -> [196.251.73.85] 50337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413236/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413236; rev:1;) alert tcp $HOME_NET any -> [115.120.250.85] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413235/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413235; rev:1;) alert tcp $HOME_NET any -> [194.5.249.178] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413234/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_16; classtype:trojan-activity; sid:91413234; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/_packetupdateapibasegeneratoruniversallocalpublic.php"; depth:54; nocase; http.host; content:"557844cm.nyashnyash.ru"; depth:22; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413231/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413231; rev:1;) alert tcp $HOME_NET any -> [51.15.15.47] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413230/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91413230; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"area51.at.bitthebyte.com"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413229/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91413229; rev:1;) alert tcp $HOME_NET any -> [195.211.190.227] 2484 (msg:"ThreatFox Quasar RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413227/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413227; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/53580e28.php"; depth:13; nocase; http.host; content:"ce11914.tw1.ru"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413226/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413226; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3023968f.php"; depth:13; nocase; http.host; content:"a1081046.xsph.ru"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413225/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413225; rev:1;) alert tcp $HOME_NET any -> [45.137.22.234] 55615 (msg:"ThreatFox RedLine Stealer botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413130/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413130; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 75%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zx5v"; depth:5; nocase; http.host; content:"20.74.209.192"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413129/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91413129; rev:1;) alert tcp $HOME_NET any -> [20.74.209.192] 4446 (msg:"ThreatFox Meterpreter botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413128/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413128; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"righqthorizon.cyou"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413124/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91413124; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"apply-sand.gl.at.ply.gg"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413123/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91413123; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"mikeykarby-41864.portmap.host"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413122/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91413122; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"bot.weizaipay.xyz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413121/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91413121; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"shewaswalking.ddns.net"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413120/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91413120; rev:1;) alert tcp $HOME_NET any -> [196.251.116.95] 444 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413119/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91413119; rev:1;) alert tcp $HOME_NET any -> [101.36.117.41] 8086 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413118/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91413118; rev:1;) alert tcp $HOME_NET any -> [185.222.58.36] 55615 (msg:"ThreatFox RedLine Stealer botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413117/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413117; rev:1;) alert tcp $HOME_NET any -> [147.185.221.25] 49564 (msg:"ThreatFox NjRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413060/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413060; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/externalhttpgameflowerwordpress.php"; depth:36; nocase; http.host; content:"pw402.castledev.ru"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413059/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413059; rev:1;) alert tcp $HOME_NET any -> [147.45.178.55] 80 (msg:"ThreatFox Stealc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413058/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413058; rev:1;) alert tcp $HOME_NET any -> [35.78.180.139] 5432 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413057/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413057; rev:1;) alert tcp $HOME_NET any -> [176.65.140.68] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413056/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413056; rev:1;) alert tcp $HOME_NET any -> [185.211.4.26] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413055/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413055; rev:1;) alert tcp $HOME_NET any -> [191.96.207.168] 6606 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413053/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413053; rev:1;) alert tcp $HOME_NET any -> [191.96.207.168] 7707 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413054/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413054; rev:1;) alert tcp $HOME_NET any -> [191.96.207.75] 6606 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413050/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413050; rev:1;) alert tcp $HOME_NET any -> [191.96.207.75] 7707 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413051/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413051; rev:1;) alert tcp $HOME_NET any -> [108.61.217.60] 8888 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413052/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413052; rev:1;) alert tcp $HOME_NET any -> [34.174.254.138] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413048/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413048; rev:1;) alert tcp $HOME_NET any -> [185.49.126.235] 6606 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413049/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413049; rev:1;) alert tcp $HOME_NET any -> [185.49.126.245] 6606 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413045/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413045; rev:1;) alert tcp $HOME_NET any -> [191.96.207.172] 6606 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413046/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413046; rev:1;) alert tcp $HOME_NET any -> [191.96.207.172] 7707 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413047/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413047; rev:1;) alert tcp $HOME_NET any -> [3.27.46.197] 8000 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413044/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413044; rev:1;) alert tcp $HOME_NET any -> [175.178.114.8] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413043/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413043; rev:1;) alert tcp $HOME_NET any -> [47.98.175.135] 8080 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413042/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413042; rev:1;) alert tcp $HOME_NET any -> [106.15.184.255] 50011 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413041/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413041; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"programs.edlester.com"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413037/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"naturewsounds.help"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413039/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91413039; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"friendseforever.help"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413038/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91413038; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"goshow.click"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413036/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"80.78.26.62"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413035/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413035; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.zamoq.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413033/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.zamoq.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413034/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413034; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.cobyw.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413031/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.cobyw.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413032/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.zovof.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413029/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413029; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.zovof.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413030/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413030; rev:1;) alert tcp $HOME_NET any -> [156.229.232.154] 51325 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413026/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91413026; rev:1;) alert tcp $HOME_NET any -> [103.214.71.8] 9931 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413027/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91413027; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"damn.biggay.space"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413028/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91413028; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.myvyt.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413023/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413023; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.myvyt.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413024/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413024; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"www.iq-insitute.org"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413025/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413025; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"65.108.88.44"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413020/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413020; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.falih.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413021/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413021; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.falih.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413022/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413022; rev:1;) alert tcp $HOME_NET any -> [195.88.218.77] 9999 (msg:"ThreatFox Unknown Stealer botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413013/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91413013; rev:1;) alert tcp $HOME_NET any -> [73.192.73.7] 9999 (msg:"ThreatFox Unknown Stealer botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413014/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91413014; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.cigog.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413016/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413016; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.cigog.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413019/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413019; rev:1;) alert tcp $HOME_NET any -> [89.117.38.234] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413018/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91413018; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"cs.lihualihua266.us.kg"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413017/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91413017; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 75%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ran_h_estia"; depth:12; nocase; http.host; content:"porannyrozruch.pl"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413011/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91413011; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 75%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/login.html"; depth:11; nocase; http.host; content:"d1ie3z.com"; depth:10; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413009/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91413009; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.nuviq.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413010/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413010; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.nuviq.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413012/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413012; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.kybax.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1413007/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413007; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.kybax.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1413008/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413008; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.qojyx.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412764/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412764; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.qojyx.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412765/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412765; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"oceanbreoeze.top"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412967/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412967; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shredder.m4a"; depth:13; nocase; http.host; content:"u1.sulkuntie.shop"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412973/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412973; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"u1.sulkuntie.shop"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412974/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412974; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/supershell/login/"; depth:18; nocase; http.host; content:"196.251.118.76"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412975/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412975; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"dynamicyspace.top"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412976/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412976; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"newhoriozons.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412977/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412977; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"lightojourney.top"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412978/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412978; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"kaleoidoscopewa.top"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412981/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412981; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"boldcyanvas.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412979/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412979; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"openncanvas.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412980/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412980; rev:1;) alert tcp $HOME_NET any -> [166.88.55.54] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412987/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412987; rev:1;) alert tcp $HOME_NET any -> [198.98.54.209] 34473 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412988/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412988; rev:1;) alert tcp $HOME_NET any -> [107.172.140.197] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412989/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412989; rev:1;) alert tcp $HOME_NET any -> [47.100.68.73] 8011 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412990/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412990; rev:1;) alert tcp $HOME_NET any -> [144.48.8.190] 8443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412991/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412991; rev:1;) alert tcp $HOME_NET any -> [218.30.103.130] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412992/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412992; rev:1;) alert tcp $HOME_NET any -> [43.242.203.34] 801 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413006/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413006; rev:1;) alert tcp $HOME_NET any -> [156.238.230.148] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413005/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413005; rev:1;) alert tcp $HOME_NET any -> [13.208.181.173] 46174 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413004/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413004; rev:1;) alert tcp $HOME_NET any -> [196.251.90.57] 2000 (msg:"ThreatFox DCRat botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413003/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413003; rev:1;) alert tcp $HOME_NET any -> [196.251.90.56] 2000 (msg:"ThreatFox DCRat botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413002/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413002; rev:1;) alert tcp $HOME_NET any -> [4.234.160.148] 443 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413001/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413001; rev:1;) alert tcp $HOME_NET any -> [69.48.202.241] 443 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412998/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412998; rev:1;) alert tcp $HOME_NET any -> [163.5.32.127] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412999/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412999; rev:1;) alert tcp $HOME_NET any -> [69.166.230.200] 2345 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1413000/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91413000; rev:1;) alert tcp $HOME_NET any -> [50.114.115.207] 7707 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412996/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412996; rev:1;) alert tcp $HOME_NET any -> [108.181.174.200] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412997/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412997; rev:1;) alert tcp $HOME_NET any -> [66.181.36.133] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412994/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412994; rev:1;) alert tcp $HOME_NET any -> [101.36.117.41] 8085 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412995/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412995; rev:1;) alert tcp $HOME_NET any -> [45.144.214.126] 4126 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412993/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412993; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"www.sistemasinaionline.com.br"; depth:29; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412986/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412986; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"lightojourney.top"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412985/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412985; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"thwrivenest.top"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412984/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412984; rev:1;) alert tcp $HOME_NET any -> [117.212.114.253] 443 (msg:"ThreatFox Ghost RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412983/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412983; rev:1;) alert tcp $HOME_NET any -> [118.122.8.157] 1911 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412982/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412982; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"octothl.ddnsfree.com"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412972/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412972; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"mirai.cinquento.publicvm.com"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412971/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412971; rev:1;) alert tcp $HOME_NET any -> [193.161.193.99] 32954 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412970/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412970; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"11111111111111111111111111111111111111112ewdsacafa-32954.portmap.host"; depth:69; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412969/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412969; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/xquvknar"; depth:13; nocase; http.host; content:"pastebin.com"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412968/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412968; rev:1;) alert tcp $HOME_NET any -> [189.14.46.162] 1182 (msg:"ThreatFox Quasar RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412966/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412966; rev:1;) alert tcp $HOME_NET any -> [39.106.5.215] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412965/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412965; rev:1;) alert tcp $HOME_NET any -> [159.89.98.93] 389 (msg:"ThreatFox Meterpreter botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412964/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412964; rev:1;) alert tcp $HOME_NET any -> [70.31.125.182] 2222 (msg:"ThreatFox QakBot botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412963/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412963; rev:1;) alert tcp $HOME_NET any -> [3.113.143.58] 443 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412962/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412962; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 19611 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412955/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412955; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 19887 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412956/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412956; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 20000 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412957/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412957; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 21135 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412958/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412958; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 24010 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412959/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412959; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 30919 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412960/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412960; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 3216 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412961/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412961; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 10443 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412950/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412950; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 12000 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412951/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412951; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 18068 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412952/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412952; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 18333 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412953/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412953; rev:1;) alert tcp $HOME_NET any -> [216.235.95.100] 18628 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412954/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412954; rev:1;) alert tcp $HOME_NET any -> [193.124.47.213] 8888 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412949/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412949; rev:1;) alert tcp $HOME_NET any -> [154.92.19.71] 19082 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412948/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412948; rev:1;) alert tcp $HOME_NET any -> [13.246.194.171] 6443 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412947/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412947; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 50%)"; dns_query; content:"eecsys.com"; depth:10; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412946/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412946; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"town-brand.gl.at.ply.gg"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412945/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412945; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"fevereiro2025.duckdns.org"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412944/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412944; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"honeypie.r-e.kr"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412941/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412941; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"hwhm.cc5.us.kg"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412942/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412942; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"zcjs888.cfd"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412943/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412943; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"www.sistemasinaionline.com.br"; depth:29; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412940/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412940; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"124.71.228.177"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412939/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412939; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"194.26.192.33"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412938/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412938; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/supershell/login"; depth:17; nocase; http.host; content:"207.174.28.89"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412937/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412937; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/di0her478/login.php"; depth:20; nocase; http.host; content:"185.215.113.209"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412936/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412936; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"joyfulnhest.top"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412935/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412935; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"aheadrarry.help"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412934/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412934; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"floweringtstrip.help"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412933/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412933; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"grzeenbreeze.cyou"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412932/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412932; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/2938eb1cc484fea4/sqlite3.dll"; depth:29; nocase; http.host; content:"83.222.191.225"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412931/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412931; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/0028a0f3432ee7b2/sqlite3.dll"; depth:29; nocase; http.host; content:"178.159.43.166"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412930/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412930; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/3b4b68059f902c42/vcruntime140.dll"; depth:34; nocase; http.host; content:"95.215.204.229"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412929/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412929; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/97f9710b31d15029/mozglue.dll"; depth:29; nocase; http.host; content:"194.87.29.53"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412928/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412928; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/6d24030469a6b14b/vcruntime140.dll"; depth:34; nocase; http.host; content:"217.196.96.228"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412927/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412927; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/f059ec3d7eb90876/vcruntime140.dll"; depth:34; nocase; http.host; content:"77.91.76.36"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412926/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412926; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/884af7b2dd911e85/sqlite3.dll"; depth:29; nocase; http.host; content:"80.85.241.225"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412925/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412925; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/126d33f6b8f9bd61/sqlite3.dll"; depth:29; nocase; http.host; content:"95.182.97.58"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412924/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412924; rev:1;) alert tcp $HOME_NET any -> [185.196.8.77] 80 (msg:"ThreatFox Broomstick botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412923/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412923; rev:1;) alert tcp $HOME_NET any -> [13.40.64.210] 2090 (msg:"ThreatFox BlackShades botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412922/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412922; rev:1;) alert tcp $HOME_NET any -> [39.105.211.255] 4445 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412921/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412921; rev:1;) alert tcp $HOME_NET any -> [103.243.25.70] 50050 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412920/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412920; rev:1;) alert tcp $HOME_NET any -> [209.97.146.219] 1433 (msg:"ThreatFox BianLian botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412919/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412919; rev:1;) alert tcp $HOME_NET any -> [209.97.146.219] 443 (msg:"ThreatFox BianLian botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412918/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412918; rev:1;) alert tcp $HOME_NET any -> [95.38.89.121] 6000 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412915/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412915; rev:1;) alert tcp $HOME_NET any -> [13.208.172.53] 2570 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412916/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412916; rev:1;) alert tcp $HOME_NET any -> [13.208.172.53] 70 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412917/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412917; rev:1;) alert tcp $HOME_NET any -> [31.171.131.83] 80 (msg:"ThreatFox MooBot botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412914/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412914; rev:1;) alert tcp $HOME_NET any -> [36.50.233.24] 60002 (msg:"ThreatFox Quasar RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412909/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412909; rev:1;) alert tcp $HOME_NET any -> [20.62.9.174] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412910/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412910; rev:1;) alert tcp $HOME_NET any -> [20.173.41.208] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412911/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412911; rev:1;) alert tcp $HOME_NET any -> [67.217.228.7] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412912/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412912; rev:1;) alert tcp $HOME_NET any -> [185.49.126.166] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412908/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412908; rev:1;) alert tcp $HOME_NET any -> [185.49.126.52] 6606 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412906/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412906; rev:1;) alert tcp $HOME_NET any -> [185.49.126.166] 6606 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412907/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412907; rev:1;) alert tcp $HOME_NET any -> [45.137.194.110] 5555 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412904/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412904; rev:1;) alert tcp $HOME_NET any -> [192.3.238.130] 5555 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412905/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412905; rev:1;) alert tcp $HOME_NET any -> [85.239.232.11] 5555 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412901/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412901; rev:1;) alert tcp $HOME_NET any -> [45.154.98.68] 5555 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412902/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412902; rev:1;) alert tcp $HOME_NET any -> [196.251.116.95] 5555 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412903/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412903; rev:1;) alert tcp $HOME_NET any -> [196.251.118.49] 789 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412900/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412900; rev:1;) alert tcp $HOME_NET any -> [172.94.53.178] 17527 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412899/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412899; rev:1;) alert tcp $HOME_NET any -> [181.50.73.64] 44622 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412898/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412898; rev:1;) alert tcp $HOME_NET any -> [54.225.170.245] 443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412896/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412896; rev:1;) alert tcp $HOME_NET any -> [181.50.73.64] 49322 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412897/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412897; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.olarmedia.xyz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412871/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412871; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.onja.shop"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412872/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412872; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.ookcovers.xyz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412873/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412873; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.oomoo.store"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412874/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412874; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.oppyworld.fun"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412875/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412875; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.panda.xyz"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412876/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412876; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.r210.info"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412877/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412877; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.rbantravelstories.online"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412878/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412878; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.regnancy-67873.bond"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412879/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412879; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.rginine555.store"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412880/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412880; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.rilby.store"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412881/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412881; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.rokidu.info"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412882/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412882; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.rotableblender.online"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412883/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412883; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.rpa.club"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412884/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412884; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.uabf.info"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412885/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412885; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.uivlio.xyz"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412886/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412886; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.unaid-jamshed.shop"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412887/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412887; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.unisitri.net"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412888/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412888; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.uto-loans-in-africa-2024.today"; depth:34; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412889/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412889; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.wefright.net"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412890/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412890; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.wnyourhealth.xyz"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412891/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412891; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.y01.vip"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412892/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412892; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.yallergies.online"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412893/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412893; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.ynthesizerwf.store"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412894/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412894; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.yskillandyou.xyz"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412895/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412895; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.dhd-treatment-42199.bond"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412846/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412846; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.ealthyzone.live"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412847/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412847; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.enamind.net"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412848/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412848; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.engdianertian.vip"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412849/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412849; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.estrated.xyz"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412850/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412850; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.eziser.fun"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412851/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412851; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.ghkp.shop"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412852/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412852; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.havuonvanthanh.store"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412853/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412853; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.hinoplasty-solutions.sbs"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412854/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412854; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.hiteelephant.online"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412855/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412855; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.igsawgame.xyz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412856/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412856; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.illyjolly.online"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412857/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412857; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.izalmart.shop"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412858/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412858; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.kipthegaames.online"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412859/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412859; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.laygroundsequipment.xyz"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412860/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412860; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.litz.baby"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412861/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412861; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.lossar.online"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412862/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412862; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.lugsq.info"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412863/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412863; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.lysiannails.art"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412864/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412864; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.mazonworld.store"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412865/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412865; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.nfluencer-marketing-38653.bond"; depth:34; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412866/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412866; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.nfoviral99.xyz"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412867/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412867; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.nitogel.skin"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412868/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412868; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.nline-advertising-37613.bond"; depth:32; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412869/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412869; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.obotquote.net"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412870/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412870; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.-avi.art"; depth:12; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412831/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412831; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.06ks7.club"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412832/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412832; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.4rcraft.online"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412833/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412833; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.92.info"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412834/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412834; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.ackcleveland.biz"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412835/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412835; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.ahjongwins3.cyou"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412836/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412836; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.aifunclub.fit"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412837/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412837; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.aixabank.video"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412838/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412838; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.aklandpt.net"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412839/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412839; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.ancasterequinemassage.net"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412840/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412840; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.aromzeciri.shop"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412841/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412841; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.bewuxi.info"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412842/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412842; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.cassg.net"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412843/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412843; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.commerce-69321.bond"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412844/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412844; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"www.d97.lat"; depth:11; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412845/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412845; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.uabf.info"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412820/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412820; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.uivlio.xyz"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412821/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412821; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.unaid-jamshed.shop"; depth:22; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412822/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.unisitri.net"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412823/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.uto-loans-in-africa-2024.today"; depth:34; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412824/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412824; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.wefright.net"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412825/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412825; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.wnyourhealth.xyz"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412826/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412826; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.y01.vip"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412827/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412827; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.yallergies.online"; depth:21; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412828/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412828; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.ynthesizerwf.store"; depth:22; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412829/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412829; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.yskillandyou.xyz"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412830/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.oomoo.store"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412809/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412809; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.oppyworld.fun"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412810/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412810; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.panda.xyz"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412811/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412811; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.r210.info"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412812/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.rbantravelstories.online"; depth:28; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412813/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.regnancy-67873.bond"; depth:23; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412814/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412814; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.rginine555.store"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412815/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412815; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.rilby.store"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412816/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412816; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.rokidu.info"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412817/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412817; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.rotableblender.online"; depth:25; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412818/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412818; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.rpa.club"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412819/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412819; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.litz.baby"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412796/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412796; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.lossar.online"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412797/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412797; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.lugsq.info"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412798/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412798; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.lysiannails.art"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412799/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412799; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.mazonworld.store"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412800/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412800; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.nfluencer-marketing-38653.bond"; depth:34; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412801/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412801; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.nfoviral99.xyz"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412802/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412802; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.nitogel.skin"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412803/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412803; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.nline-advertising-37613.bond"; depth:32; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412804/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412804; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.obotquote.net"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412805/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412805; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.olarmedia.xyz"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412806/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412806; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.onja.shop"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412807/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412807; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.ookcovers.xyz"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412808/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412808; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.engdianertian.vip"; depth:21; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412784/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412784; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.estrated.xyz"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412785/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412785; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.eziser.fun"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412786/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412786; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.ghkp.shop"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412787/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412787; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.havuonvanthanh.store"; depth:24; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412788/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412788; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.hinoplasty-solutions.sbs"; depth:28; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412789/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412789; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.hiteelephant.online"; depth:23; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412790/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412790; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.igsawgame.xyz"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412791/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.illyjolly.online"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412792/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.izalmart.shop"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412793/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412793; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.kipthegaames.online"; depth:23; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412794/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412794; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.laygroundsequipment.xyz"; depth:27; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412795/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412795; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.aifunclub.fit"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412772/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412772; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.aixabank.video"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412773/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412773; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.aklandpt.net"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412774/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412774; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.ancasterequinemassage.net"; depth:29; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412775/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412775; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.aromzeciri.shop"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412776/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412776; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.bewuxi.info"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412777/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.cassg.net"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412778/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.commerce-69321.bond"; depth:23; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412779/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.d97.lat"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412780/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412780; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.dhd-treatment-42199.bond"; depth:28; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412781/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.ealthyzone.live"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412782/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.enamind.net"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412783/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.06ks7.club"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412767/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.4rcraft.online"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412768/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412768; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.92.info"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412769/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412769; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.ackcleveland.biz"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412770/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412770; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/o10c/"; depth:6; nocase; http.host; content:"www.ahjongwins3.cyou"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412771/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_15; classtype:trojan-activity; sid:91412771; rev:1;) alert tcp $HOME_NET any -> [45.128.233.86] 666 (msg:"ThreatFox Bashlite botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412763/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412763; rev:1;) alert tcp $HOME_NET any -> [13.212.252.171] 443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412761/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412761; rev:1;) alert tcp $HOME_NET any -> [129.148.50.46] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412762/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412762; rev:1;) alert tcp $HOME_NET any -> [130.193.38.97] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412760/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412760; rev:1;) alert tcp $HOME_NET any -> [52.28.140.148] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412759/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412759; rev:1;) alert tcp $HOME_NET any -> [3.80.158.35] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412757/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412757; rev:1;) alert tcp $HOME_NET any -> [195.13.250.6] 18080 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412758/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412758; rev:1;) alert tcp $HOME_NET any -> [113.45.247.53] 443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412755/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412755; rev:1;) alert tcp $HOME_NET any -> [13.61.104.185] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412756/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412756; rev:1;) alert tcp $HOME_NET any -> [191.113.105.175] 8080 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412753/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412753; rev:1;) alert tcp $HOME_NET any -> [18.188.97.184] 8080 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412754/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412754; rev:1;) alert tcp $HOME_NET any -> [64.23.191.114] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412751/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412751; rev:1;) alert tcp $HOME_NET any -> [44.229.7.211] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412749/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412749; rev:1;) alert tcp $HOME_NET any -> [45.152.65.126] 33335 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412750/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412750; rev:1;) alert tcp $HOME_NET any -> [3.209.210.98] 443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412752/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412752; rev:1;) alert tcp $HOME_NET any -> [45.79.22.72] 623 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412746/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412746; rev:1;) alert tcp $HOME_NET any -> [170.187.142.123] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412747/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412747; rev:1;) alert tcp $HOME_NET any -> [91.208.240.178] 60000 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412748/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412748; rev:1;) alert tcp $HOME_NET any -> [172.236.131.202] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412744/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412744; rev:1;) alert tcp $HOME_NET any -> [172.233.120.168] 88 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412745/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412745; rev:1;) alert tcp $HOME_NET any -> [172.236.212.22] 536 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412742/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412742; rev:1;) alert tcp $HOME_NET any -> [45.56.126.27] 286 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412743/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412743; rev:1;) alert tcp $HOME_NET any -> [172.235.174.215] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412741/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412741; rev:1;) alert tcp $HOME_NET any -> [172.236.32.251] 830 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412739/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412739; rev:1;) alert tcp $HOME_NET any -> [139.144.210.30] 103 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412740/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412740; rev:1;) alert tcp $HOME_NET any -> [45.56.126.247] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412735/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412735; rev:1;) alert tcp $HOME_NET any -> [139.144.198.214] 1497 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412736/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412736; rev:1;) alert tcp $HOME_NET any -> [172.233.120.84] 771 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412737/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412737; rev:1;) alert tcp $HOME_NET any -> [45.56.67.65] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412738/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412738; rev:1;) alert tcp $HOME_NET any -> [144.24.203.92] 5000 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412733/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412733; rev:1;) alert tcp $HOME_NET any -> [139.162.8.226] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412734/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412734; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sso.demoforecl.in"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412731/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412731; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ec2-52-74-224-241.ap-southeast-1.compute.amazonaws.com"; depth:54; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412732/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412732; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"softdaqwn.cyou"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412671/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412671; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"truefbloom.cyou"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412673/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412673; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"urbantraoil.cyou"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412674/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412674; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"softpafthway.cyou"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412672/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412672; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"zengardxen.cyou"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412675/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412675; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"skywarddnream.top"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412687/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412687; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"flourishpyoint.top"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412688/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412688; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"swafeharbor.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412689/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412689; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"joyfulnhest.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412690/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412690; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"hoarmonynest.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412691/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412691; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"purehnorizon.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412692/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412692; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"echhopoint.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412693/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412693; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"www.assignmenttelevision.info"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412694/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412694; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"wisyefuture.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412696/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412696; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"minndfulpath.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412695/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412695; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"viytalburst.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412697/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412697; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"motivaotedsoul.top"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412700/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412700; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"imoaginesphere.top"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412698/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412698; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"elevatemyind.top"; depth:16; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412699/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412699; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"kindsprohut.top"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412701/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412701; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"grzeenbreeze.cyou"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412670/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412670; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.qahov.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412653/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412653; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"boldquestq.cyou"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412668/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412668; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"calmquzest.cyou"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412669/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412669; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"quiwetwaveso.top"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412667/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412667; rev:1;) alert tcp $HOME_NET any -> [124.71.228.177] 9991 (msg:"ThreatFox Chaos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412654/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412654; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.limev.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412651/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412651; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.qahov.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412652/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412652; rev:1;) alert tcp $HOME_NET any -> [96.9.124.130] 443 (msg:"ThreatFox Latrodectus botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412730/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412730; rev:1;) alert tcp $HOME_NET any -> [194.85.251.38] 8080 (msg:"ThreatFox Bashlite botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412729/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412729; rev:1;) alert tcp $HOME_NET any -> [18.118.47.63] 4840 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412728/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412728; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"hook.dayangpay.com"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412727/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412727; rev:1;) alert tcp $HOME_NET any -> [191.96.207.75] 2004 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412725/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412725; rev:1;) alert tcp $HOME_NET any -> [181.41.194.91] 6004 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412726/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412726; rev:1;) alert tcp $HOME_NET any -> [193.23.3.29] 2404 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412724/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412724; rev:1;) alert tcp $HOME_NET any -> [47.239.165.225] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412723/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412723; rev:1;) alert tcp $HOME_NET any -> [95.179.141.132] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412722/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412722; rev:1;) alert tcp $HOME_NET any -> [52.71.181.100] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412721/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412721; rev:1;) alert tcp $HOME_NET any -> [40.112.213.212] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412720/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412720; rev:1;) alert tcp $HOME_NET any -> [18.130.134.61] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412719/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412719; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"ega.serveblog.net"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412718/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412718; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"cld.cnkalciwcm.online"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412717/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_15; classtype:trojan-activity; sid:91412717; rev:1;) alert tcp $HOME_NET any -> [24.152.38.77] 481 (msg:"ThreatFox NjRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412716/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/351a63c9.php"; depth:13; nocase; http.host; content:"a1083519.xsph.ru"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412715/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412715; rev:1;) alert tcp $HOME_NET any -> [91.209.135.199] 4000 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412714/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412714; rev:1;) alert tcp $HOME_NET any -> [201.43.52.170] 8081 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412713/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412713; rev:1;) alert tcp $HOME_NET any -> [78.135.93.218] 8443 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412712/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412712; rev:1;) alert tcp $HOME_NET any -> [88.80.148.30] 1604 (msg:"ThreatFox Quasar RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412711/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412711; rev:1;) alert tcp $HOME_NET any -> [18.143.214.68] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412709/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412709; rev:1;) alert tcp $HOME_NET any -> [52.74.224.241] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412710/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412710; rev:1;) alert tcp $HOME_NET any -> [191.96.207.227] 8888 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412708/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412708; rev:1;) alert tcp $HOME_NET any -> [45.133.180.154] 8808 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412707/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412707; rev:1;) alert tcp $HOME_NET any -> [206.123.152.48] 3191 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412706/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412706; rev:1;) alert tcp $HOME_NET any -> [172.111.216.71] 2404 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412704/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412704; rev:1;) alert tcp $HOME_NET any -> [172.111.137.68] 2889 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412705/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412705; rev:1;) alert tcp $HOME_NET any -> [176.65.141.64] 443 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412703/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412703; rev:1;) alert tcp $HOME_NET any -> [51.15.15.47] 8443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412702/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_15; classtype:trojan-activity; sid:91412702; rev:1;) alert tcp $HOME_NET any -> [147.185.221.25] 51413 (msg:"ThreatFox NjRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412686/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412686; rev:1;) alert tcp $HOME_NET any -> [180.76.138.238] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412685/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412685; rev:1;) alert tcp $HOME_NET any -> [96.28.226.110] 8080 (msg:"ThreatFox DeimosC2 botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412684/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412684; rev:1;) alert tcp $HOME_NET any -> [79.119.16.118] 443 (msg:"ThreatFox QakBot botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412683/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412683; rev:1;) alert tcp $HOME_NET any -> [78.183.223.200] 443 (msg:"ThreatFox QakBot botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412682/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412682; rev:1;) alert tcp $HOME_NET any -> [70.31.125.162] 2222 (msg:"ThreatFox QakBot botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412681/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412681; rev:1;) alert tcp $HOME_NET any -> [3.131.99.8] 35798 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412680/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412680; rev:1;) alert tcp $HOME_NET any -> [189.140.12.177] 443 (msg:"ThreatFox QakBot botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412679/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412679; rev:1;) alert tcp $HOME_NET any -> [178.17.170.139] 443 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412678/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412678; rev:1;) alert tcp $HOME_NET any -> [163.172.178.82] 40056 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412677/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412677; rev:1;) alert tcp $HOME_NET any -> [103.27.186.143] 8888 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412676/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412676; rev:1;) alert tcp $HOME_NET any -> [89.185.80.159] 443 (msg:"ThreatFox DanaBot botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412666/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412666; rev:1;) alert tcp $HOME_NET any -> [89.185.80.87] 443 (msg:"ThreatFox DanaBot botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412665/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412665; rev:1;) alert tcp $HOME_NET any -> [89.185.80.116] 443 (msg:"ThreatFox DanaBot botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412664/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412664; rev:1;) alert tcp $HOME_NET any -> [85.239.54.183] 7833 (msg:"ThreatFox BianLian botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412662/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412662; rev:1;) alert tcp $HOME_NET any -> [46.243.7.173] 8080 (msg:"ThreatFox BianLian botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412663/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412663; rev:1;) alert tcp $HOME_NET any -> [209.141.32.15] 80 (msg:"ThreatFox MooBot botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412661/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412661; rev:1;) alert tcp $HOME_NET any -> [13.56.182.60] 8037 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412660/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412660; rev:1;) alert tcp $HOME_NET any -> [190.89.245.97] 3000 (msg:"ThreatFox DCRat botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412659/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412659; rev:1;) alert tcp $HOME_NET any -> [207.174.28.89] 8888 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412658/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412658; rev:1;) alert tcp $HOME_NET any -> [185.157.162.168] 1990 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412657/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412657; rev:1;) alert tcp $HOME_NET any -> [162.33.178.61] 5000 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412656/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412656; rev:1;) alert tcp $HOME_NET any -> [194.163.180.87] 4433 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412655/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412655; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.limev.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412649/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412649; rev:1;) alert tcp $HOME_NET any -> [181.49.105.59] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412650/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412650; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"scrofil57.mzip.partners"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412638/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412638; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"scrogunim.vizpaz.express"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412639/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412639; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sprogunpansar50.zurichaxon.partners"; depth:35; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412640/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412640; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"spromantum.restonline.express"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412641/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412641; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"spruvingem.mzip.partners"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412642/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412642; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"strisantum.zurichaxon.partners"; depth:30; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412643/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412643; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"trevir.vizpaz.express"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412644/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412644; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"trisonronmol.restonline.express"; depth:31; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412645/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412645; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"vamintentum.vizpaz.express"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412646/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412646; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"vaval424.restonline.express"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412647/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412647; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"vaxil.mzip.partners"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412648/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412648; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"gramzinconrol.vizpaz.express"; depth:28; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412615/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412615; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"grapansar627.restonline.express"; depth:31; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412616/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412616; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"plancol.keepnowz.org"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412617/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412617; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"plelinguntum.restonline.express"; depth:31; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412618/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412618; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"plolinmangem43.keepnowz.org"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412619/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412619; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"plolinvintez44.zurichaxon.partners"; depth:34; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412620/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412620; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"plominsanvel.keepnowz.org"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412621/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412621; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ploqual.keepnowz.org"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412622/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412622; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"prapenqual.vizpaz.express"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412623/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412623; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"prapinhenhal.restonline.express"; depth:31; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412624/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412624; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"prefar.vizpaz.express"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412625/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412625; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"prelinmenel.keepnowz.org"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412626/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412626; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"prepaz.mzip.partners"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412627/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412627; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"pritanpor81.mzip.partners"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412628/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412628; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"privel.mzip.partners"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412629/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412629; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"probansonral.mzip.partners"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412630/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412630; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"procil.vizpaz.express"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412631/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412631; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"promongongor87.keepnowz.org"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412632/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412632; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"promonmol01.mzip.partners"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412633/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412633; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"pruxil.vizpaz.express"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412634/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412634; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"scriguncansal.zurichaxon.partners"; depth:33; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412635/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412635; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"scrigunminvir.zurichaxon.partners"; depth:33; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412636/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412636; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"scriwingem.keepnowz.org"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412637/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412637; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"clanancal.keepnowz.org"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412594/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412594; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"clesal.keepnowz.org"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412595/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412595; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cragor.keepnowz.org"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412596/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412596; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"craronqual.vizpaz.express"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412597/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412597; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cretonroncol.zurichaxon.partners"; depth:32; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412598/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412598; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cricol28.restonline.express"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412599/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412599; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"crihal28.vizpaz.express"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412600/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412600; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"crocal.vizpaz.express"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412601/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412601; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"crolunral.keepnowz.org"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412602/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412602; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"croronnonwel.restonline.express"; depth:31; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412603/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412603; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"dratunlintil.restonline.express"; depth:31; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412604/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412604; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"flibangongor.vizpaz.express"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412605/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412605; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"flimonxoncol.restonline.express"; depth:31; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412606/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412606; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"flipinjanfer.vizpaz.express"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412607/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412607; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"flomennil.mzip.partners"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412608/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412608; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"frajal.mzip.partners"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412609/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412609; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"gluqual.zurichaxon.partners"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412610/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412610; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"graal.restonline.express"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412611/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412611; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"gragem.keepnowz.org"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412612/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412612; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"gramdinmincil.keepnowz.org"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412613/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412613; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"graminvel.keepnowz.org"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412614/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412614; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"blogongor.zurichaxon.partners"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412587/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412587; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"blosal.zurichaxon.partners"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412588/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412588; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"blosil.restonline.express"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412589/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412589; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"blubenfunsul.restonline.express"; depth:31; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412590/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412590; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"blufel3.vizpaz.express"; depth:22; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412591/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412591; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"brumonnanbel.zurichaxon.partners"; depth:32; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412592/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412592; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"clajansonsul.vizpaz.express"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412593/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412593; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.bejim.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412585/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412585; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.bejim.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412586/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412586; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.xibal.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412581/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412581; rev:1;) alert tcp $HOME_NET any -> [154.23.163.214] 1995 (msg:"ThreatFox Mirai botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412582/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412582; rev:1;) alert tcp $HOME_NET any -> [79.110.49.89] 4251 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412584/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412584; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"0928fax.home-webserver.de"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412583/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412583; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.xibal.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412580/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412580; rev:1;) alert tcp $HOME_NET any -> [139.99.86.21] 2003 (msg:"ThreatFox XenoRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412579/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412579; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.kamaj.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412577/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412577; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.kamaj.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412578/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412578; rev:1;) alert tcp $HOME_NET any -> [172.67.190.1] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412418/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412418; rev:1;) alert tcp $HOME_NET any -> [172.67.216.218] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412419/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412419; rev:1;) alert tcp $HOME_NET any -> [45.66.231.11] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412416/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412416; rev:1;) alert tcp $HOME_NET any -> [77.90.36.93] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412417/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412417; rev:1;) alert tcp $HOME_NET any -> [94.154.34.23] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412413/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412413; rev:1;) alert tcp $HOME_NET any -> [45.200.148.13] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412414/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412414; rev:1;) alert tcp $HOME_NET any -> [159.65.161.159] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412415/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412415; rev:1;) alert tcp $HOME_NET any -> [62.72.29.99] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412411/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412411; rev:1;) alert tcp $HOME_NET any -> [92.113.27.107] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412410/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412410; rev:1;) alert tcp $HOME_NET any -> [13.60.214.163] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412412/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412412; rev:1;) alert tcp $HOME_NET any -> [145.223.73.54] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412408/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412408; rev:1;) alert tcp $HOME_NET any -> [154.216.16.91] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412409/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412409; rev:1;) alert tcp $HOME_NET any -> [64.95.12.254] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412405/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412405; rev:1;) alert tcp $HOME_NET any -> [31.13.224.82] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412406/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412406; rev:1;) alert tcp $HOME_NET any -> [46.250.233.59] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412407/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412407; rev:1;) alert tcp $HOME_NET any -> [87.251.78.130] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412404/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412404; rev:1;) alert tcp $HOME_NET any -> [154.216.19.217] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412403/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412403; rev:1;) alert tcp $HOME_NET any -> [154.216.20.225] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412401/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412401; rev:1;) alert tcp $HOME_NET any -> [93.127.175.11] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412402/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412402; rev:1;) alert tcp $HOME_NET any -> [154.216.20.210] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412398/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412398; rev:1;) alert tcp $HOME_NET any -> [185.11.61.95] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412399/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412399; rev:1;) alert tcp $HOME_NET any -> [154.216.19.101] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412400/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412400; rev:1;) alert tcp $HOME_NET any -> [147.93.98.67] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412397/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412397; rev:1;) alert tcp $HOME_NET any -> [178.128.157.196] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412393/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412393; rev:1;) alert tcp $HOME_NET any -> [172.67.202.225] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412426/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412426; rev:1;) alert tcp $HOME_NET any -> [172.67.177.168] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412427/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412427; rev:1;) alert tcp $HOME_NET any -> [172.67.130.168] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412428/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412428; rev:1;) alert tcp $HOME_NET any -> [172.67.197.24] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412429/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412429; rev:1;) alert tcp $HOME_NET any -> [188.114.97.3] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412431/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412431; rev:1;) alert tcp $HOME_NET any -> [172.67.217.87] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412432/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412432; rev:1;) alert tcp $HOME_NET any -> [172.67.168.130] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412434/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412434; rev:1;) alert tcp $HOME_NET any -> [172.67.136.97] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412435/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412435; rev:1;) alert tcp $HOME_NET any -> [104.21.16.237] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412437/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412437; rev:1;) alert tcp $HOME_NET any -> [172.67.157.36] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412440/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412440; rev:1;) alert tcp $HOME_NET any -> [104.21.83.17] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412442/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412442; rev:1;) alert tcp $HOME_NET any -> [104.21.16.35] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412445/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412445; rev:1;) alert tcp $HOME_NET any -> [104.21.9.24] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412446/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412446; rev:1;) alert tcp $HOME_NET any -> [172.67.212.42] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412447/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412447; rev:1;) alert tcp $HOME_NET any -> [172.67.139.68] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412449/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412449; rev:1;) alert tcp $HOME_NET any -> [104.21.74.190] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412454/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412454; rev:1;) alert tcp $HOME_NET any -> [41.216.188.85] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412455/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412455; rev:1;) alert tcp $HOME_NET any -> [91.92.241.109] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412456/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412456; rev:1;) alert tcp $HOME_NET any -> [41.216.188.84] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412457/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412457; rev:1;) alert tcp $HOME_NET any -> [185.250.207.234] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412458/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412458; rev:1;) alert tcp $HOME_NET any -> [85.209.153.135] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412459/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412459; rev:1;) alert tcp $HOME_NET any -> [45.156.25.186] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412460/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412460; rev:1;) alert tcp $HOME_NET any -> [185.80.128.162] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412461/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412461; rev:1;) alert tcp $HOME_NET any -> [5.42.92.29] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412462/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412462; rev:1;) alert tcp $HOME_NET any -> [3.15.150.119] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412463/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412463; rev:1;) alert tcp $HOME_NET any -> [94.156.8.183] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412464/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412464; rev:1;) alert tcp $HOME_NET any -> [91.200.151.233] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412465/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412465; rev:1;) alert tcp $HOME_NET any -> [89.23.97.34] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412466/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412466; rev:1;) alert tcp $HOME_NET any -> [202.79.172.198] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412467/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412467; rev:1;) alert tcp $HOME_NET any -> [161.35.109.123] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412468/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412468; rev:1;) alert tcp $HOME_NET any -> [83.147.245.71] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412469/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412469; rev:1;) alert tcp $HOME_NET any -> [91.215.85.145] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412470/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412470; rev:1;) alert tcp $HOME_NET any -> [212.118.38.66] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412471/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412471; rev:1;) alert tcp $HOME_NET any -> [45.139.199.175] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412473/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412473; rev:1;) alert tcp $HOME_NET any -> [194.33.191.252] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412472/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412472; rev:1;) alert tcp $HOME_NET any -> [20.195.201.245] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412474/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412474; rev:1;) alert tcp $HOME_NET any -> [202.79.172.225] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412475/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412475; rev:1;) alert tcp $HOME_NET any -> [134.255.233.83] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412476/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412476; rev:1;) alert tcp $HOME_NET any -> [193.233.254.5] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412477/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412477; rev:1;) alert tcp $HOME_NET any -> [40.67.240.145] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412478/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412478; rev:1;) alert tcp $HOME_NET any -> [142.132.236.35] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412479/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412479; rev:1;) alert tcp $HOME_NET any -> [172.201.108.245] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412480/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412480; rev:1;) alert tcp $HOME_NET any -> [185.229.224.110] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412481/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412481; rev:1;) alert tcp $HOME_NET any -> [159.203.158.196] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412482/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412482; rev:1;) alert tcp $HOME_NET any -> [192.129.227.114] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412483/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412483; rev:1;) alert tcp $HOME_NET any -> [158.220.98.78] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412484/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412484; rev:1;) alert tcp $HOME_NET any -> [202.79.172.236] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412485/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412485; rev:1;) alert tcp $HOME_NET any -> [45.67.229.93] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412486/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412486; rev:1;) alert tcp $HOME_NET any -> [194.146.13.49] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412487/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412487; rev:1;) alert tcp $HOME_NET any -> [98.71.9.211] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412488/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412488; rev:1;) alert tcp $HOME_NET any -> [159.69.86.27] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412489/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412489; rev:1;) alert tcp $HOME_NET any -> [159.69.146.11] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412490/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412490; rev:1;) alert tcp $HOME_NET any -> [20.163.83.232] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412491/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412491; rev:1;) alert tcp $HOME_NET any -> [192.129.227.115] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412492/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412492; rev:1;) alert tcp $HOME_NET any -> [67.205.180.81] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412493/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412493; rev:1;) alert tcp $HOME_NET any -> [192.129.227.116] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412494/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412494; rev:1;) alert tcp $HOME_NET any -> [194.26.192.208] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412495/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412495; rev:1;) alert tcp $HOME_NET any -> [194.33.191.111] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412496/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412496; rev:1;) alert tcp $HOME_NET any -> [194.33.191.6] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412497/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412497; rev:1;) alert tcp $HOME_NET any -> [192.129.227.118] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412500/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412500; rev:1;) alert tcp $HOME_NET any -> [37.247.108.171] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412498/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412498; rev:1;) alert tcp $HOME_NET any -> [192.129.227.117] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412499/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412499; rev:1;) alert tcp $HOME_NET any -> [91.92.247.135] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412501/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412501; rev:1;) alert tcp $HOME_NET any -> [91.92.242.104] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412502/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412502; rev:1;) alert tcp $HOME_NET any -> [64.176.214.26] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412503/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412503; rev:1;) alert tcp $HOME_NET any -> [87.248.157.219] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412504/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412504; rev:1;) alert tcp $HOME_NET any -> [193.164.4.60] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412507/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412507; rev:1;) alert tcp $HOME_NET any -> [192.236.160.70] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412505/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412505; rev:1;) alert tcp $HOME_NET any -> [193.164.4.109] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412506/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412506; rev:1;) alert tcp $HOME_NET any -> [161.35.235.125] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412508/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412508; rev:1;) alert tcp $HOME_NET any -> [154.82.81.80] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412509/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412509; rev:1;) alert tcp $HOME_NET any -> [185.174.136.186] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412510/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412510; rev:1;) alert tcp $HOME_NET any -> [109.107.189.97] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412511/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412511; rev:1;) alert tcp $HOME_NET any -> [45.11.181.30] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412512/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412512; rev:1;) alert tcp $HOME_NET any -> [154.204.60.134] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412514/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412514; rev:1;) alert tcp $HOME_NET any -> [160.20.109.76] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412513/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412513; rev:1;) alert tcp $HOME_NET any -> [103.189.88.164] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412515/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412515; rev:1;) alert tcp $HOME_NET any -> [37.247.108.194] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412516/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412516; rev:1;) alert tcp $HOME_NET any -> [157.7.114.81] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412517/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412517; rev:1;) alert tcp $HOME_NET any -> [91.92.249.104] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412518/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412518; rev:1;) alert tcp $HOME_NET any -> [83.222.8.13] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412519/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412519; rev:1;) alert tcp $HOME_NET any -> [213.142.157.146] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412521/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412521; rev:1;) alert tcp $HOME_NET any -> [103.241.66.221] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412520/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412520; rev:1;) alert tcp $HOME_NET any -> [193.233.161.220] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412522/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412522; rev:1;) alert tcp $HOME_NET any -> [87.248.157.149] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412523/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412523; rev:1;) alert tcp $HOME_NET any -> [37.49.230.236] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412524/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412524; rev:1;) alert tcp $HOME_NET any -> [91.92.254.28] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412525/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412525; rev:1;) alert tcp $HOME_NET any -> [178.23.190.21] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412526/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412526; rev:1;) alert tcp $HOME_NET any -> [143.110.185.89] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412527/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412527; rev:1;) alert tcp $HOME_NET any -> [209.141.36.46] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412528/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412528; rev:1;) alert tcp $HOME_NET any -> [91.92.249.18] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412529/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412529; rev:1;) alert tcp $HOME_NET any -> [13.215.161.69] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412530/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412530; rev:1;) alert tcp $HOME_NET any -> [20.39.184.218] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412531/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412531; rev:1;) alert tcp $HOME_NET any -> [165.22.44.147] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412532/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412532; rev:1;) alert tcp $HOME_NET any -> [91.215.85.153] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412535/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412535; rev:1;) alert tcp $HOME_NET any -> [82.147.85.73] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412536/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412536; rev:1;) alert tcp $HOME_NET any -> [85.209.11.82] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412534/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412534; rev:1;) alert tcp $HOME_NET any -> [193.46.56.124] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412537/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412537; rev:1;) alert tcp $HOME_NET any -> [45.66.230.72] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412538/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412538; rev:1;) alert tcp $HOME_NET any -> [94.156.253.67] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412539/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412539; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mtbiytaymtk0nzjj/"; depth:18; nocase; http.host; content:"fdgdgdfgdfgfg.top"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412559/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_14; classtype:trojan-activity; sid:91412559; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mtbiytaymtk0nzjj/"; depth:18; nocase; http.host; content:"rvrfvfvrfvfvrfvrrfv.life"; depth:24; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412558/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_14; classtype:trojan-activity; sid:91412558; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mtbiytaymtk0nzjj/"; depth:18; nocase; http.host; content:"dasdasafasdcsacas.xyz"; depth:21; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412560/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_14; classtype:trojan-activity; sid:91412560; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mtbiytaymtk0nzjj/"; depth:18; nocase; http.host; content:"cascscascdcascascdsd.info"; depth:25; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412561/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_14; classtype:trojan-activity; sid:91412561; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mtbiytaymtk0nzjj/"; depth:18; nocase; http.host; content:"alskjdlkasjlkjadljs.hk"; depth:22; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412562/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_14; classtype:trojan-activity; sid:91412562; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mtbiytaymtk0nzjj/"; depth:18; nocase; http.host; content:"dcwdcsdcsdcsdcdscsdcs.hk"; depth:24; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412563/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_14; classtype:trojan-activity; sid:91412563; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"peakaspiroe.top"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412566/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412566; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"shiningrstars.help"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412567/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412567; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.barun.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412571/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412571; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.barun.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412573/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412573; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"greehnvibe.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412540/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412540; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 80%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mtbiytaymtk0nzjj/"; depth:18; nocase; http.host; content:"vsdcvsdvdvdsvddvs.xyz"; depth:21; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412557/; target:src_ip; metadata: confidence_level 80, first_seen 2025_02_14; classtype:trojan-activity; sid:91412557; rev:1;) alert tcp $HOME_NET any -> [72.5.42.164] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412392/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412392; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/work/original.js"; depth:17; nocase; http.host; content:"juehaicihang01.shop"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412386/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412386; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/work/index.php"; depth:15; nocase; http.host; content:"juehaicihang01.shop"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412388/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412388; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/772a09d8ce7f9f4da9fc0087f1cf84f12aedb2e2cfbf9989.bin"; depth:53; nocase; http.host; content:"ly.aoaee.shop"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412384/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412384; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"ly.aoaee.shop"; depth:13; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412385/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412385; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"juehaicihang01.shop"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412387/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412387; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/work/file.php"; depth:14; nocase; http.host; content:"juehaicihang01.shop"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412389/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/33.zip"; depth:7; nocase; http.host; content:"foxauthority.com"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412390/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412390; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"exchange.tuckx.com"; depth:18; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412391/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412391; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; nocase; http.host; content:"123.14.85.252"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412576/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412576; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; nocase; http.host; content:"117.253.225.37"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412575/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412575; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/art.php"; depth:8; nocase; http.host; content:"paperframe.xyz"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412574/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412574; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"dreamerfruits.cloud"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412572/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412572; rev:1;) alert tcp $HOME_NET any -> [134.122.128.89] 1234 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412570/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412570; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"www.elevatemyind.top"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412569/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412569; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 75%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/g.pixel"; depth:8; nocase; http.host; content:"113.44.48.28"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412568/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412568; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"xu2.201008281.xyz"; depth:17; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412565/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412565; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"xu2.201008281.xyz"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412564/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412564; rev:1;) alert tcp $HOME_NET any -> [154.38.118.126] 6688 (msg:"ThreatFox ValleyRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412556/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412556; rev:1;) alert tcp $HOME_NET any -> [45.137.22.165] 55615 (msg:"ThreatFox RedLine Stealer botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412555/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412555; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"www.monkey-proxy-999.online"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412554/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412554; rev:1;) alert tcp $HOME_NET any -> [103.245.231.9] 80 (msg:"ThreatFox ERMAC botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412553/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412553; rev:1;) alert tcp $HOME_NET any -> [192.142.18.32] 80 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412551/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412551; rev:1;) alert tcp $HOME_NET any -> [51.89.22.146] 40056 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412552/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412552; rev:1;) alert tcp $HOME_NET any -> [54.251.124.7] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412550/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412550; rev:1;) alert tcp $HOME_NET any -> [89.147.111.169] 7443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412549/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412549; rev:1;) alert tcp $HOME_NET any -> [196.251.116.95] 4444 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412547/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412547; rev:1;) alert tcp $HOME_NET any -> [146.70.158.209] 5555 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412548/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412548; rev:1;) alert tcp $HOME_NET any -> [49.113.78.2] 8888 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412545/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412545; rev:1;) alert tcp $HOME_NET any -> [113.45.235.255] 8888 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412546/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412546; rev:1;) alert tcp $HOME_NET any -> [172.245.123.49] 8690 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412543/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412543; rev:1;) alert tcp $HOME_NET any -> [104.234.204.180] 2404 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412544/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412544; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 75%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"zengardxen.cyou"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412542/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412542; rev:1;) alert tcp $HOME_NET any -> [101.43.121.110] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412541/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412541; rev:1;) alert tcp $HOME_NET any -> [181.50.73.64] 51522 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412382/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412382; rev:1;) alert tcp $HOME_NET any -> [181.50.73.64] 53722 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412383/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412383; rev:1;) alert tcp $HOME_NET any -> [51.159.55.59] 53722 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412380/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412380; rev:1;) alert tcp $HOME_NET any -> [18.219.218.39] 19 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412381/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412381; rev:1;) alert tcp $HOME_NET any -> [165.192.82.179] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412379/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412379; rev:1;) alert tcp $HOME_NET any -> [5.153.144.10] 1604 (msg:"ThreatFox DarkComet botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412378/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412378; rev:1;) alert tcp $HOME_NET any -> [176.111.144.237] 7777 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412377/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412377; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.qejym.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412375/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412375; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.qejym.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412376/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412376; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.boguj.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412365/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412365; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.boguj.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412366/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412366; rev:1;) alert tcp $HOME_NET any -> [40.112.215.1] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412371/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412371; rev:1;) alert tcp $HOME_NET any -> [40.112.215.1] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412372/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412372; rev:1;) alert tcp $HOME_NET any -> [40.112.215.76] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412373/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412373; rev:1;) alert tcp $HOME_NET any -> [40.112.215.76] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412374/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412374; rev:1;) alert tcp $HOME_NET any -> [40.112.213.212] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412370/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412370; rev:1;) alert tcp $HOME_NET any -> [108.129.139.120] 80 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412369/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412369; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"usahealthcare.publicvm.com"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412368/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412368; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"healthnet.azurefd.net"; depth:21; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412367/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412367; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"view.smartapply.resumeexpert.cloud"; depth:34; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412354/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412354; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"get.smartapply.resumeexpert.cloud"; depth:33; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412355/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412355; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.smartapply.resumeexpert.cloud"; depth:35; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412356/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412356; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"cvjet.resumeexpert.cloud"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412357/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412357; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"caps.resumeexpert.cloud"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412358/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412358; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"seek.resumeexpert.cloud"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412359/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412359; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"cv.smartapply.indeed.resumeexpert.cloud"; depth:39; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412362/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412362; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"cvsend.resumeexpert.cloud"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412360/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412360; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"send.resumeexpert.cloud"; depth:23; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412361/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412361; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"get.indeed.resumeexpert.cloud"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412363/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412363; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"tmp01.resumeexpert.cloud"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412364/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412364; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mozi.m"; depth:7; nocase; http.host; content:"221.0.220.13"; depth:12; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412353/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412353; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ccpaco.blueskyanalytics.net"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412339/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412339; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"njaco.blueskyanalytics.net"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412340/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412340; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"gcaco.blueskyanalytics.net"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412337/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412337; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"gwaco.blueskyanalytics.net"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412338/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412338; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"pbaco.blueskyanalytics.net"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412335/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412335; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"adaco.blueskyanalytics.net"; depth:26; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412336/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412336; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"caco.blueskyanalytics.net"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412334/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"www.passengerinteraction.info"; depth:29; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412328/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412328; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"aesthzeticday.top"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412329/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412329; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"contributioninspection.info"; depth:27; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412330/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/shredder.m4a"; depth:13; nocase; http.host; content:"u1.snorehedging.shop"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412332/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412332; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"u1.snorehedging.shop"; depth:20; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412333/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412333; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.dibeq.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412326/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412326; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.dibeq.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412327/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412327; rev:1;) alert tcp $HOME_NET any -> [196.251.66.105] 3608 (msg:"ThreatFox STRRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412352/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412352; rev:1;) alert tcp $HOME_NET any -> [196.251.90.74] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412350/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412350; rev:1;) alert tcp $HOME_NET any -> [146.70.158.214] 4000 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412351/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412351; rev:1;) alert tcp $HOME_NET any -> [196.251.84.193] 80 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412349/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412349; rev:1;) alert tcp $HOME_NET any -> [54.218.252.88] 9999 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412348/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412348; rev:1;) alert tcp $HOME_NET any -> [23.227.203.225] 15443 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412347/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412347; rev:1;) alert tcp $HOME_NET any -> [120.26.68.165] 14782 (msg:"ThreatFox Quasar RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412346/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412346; rev:1;) alert tcp $HOME_NET any -> [18.136.39.188] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412345/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412345; rev:1;) alert tcp $HOME_NET any -> [85.209.128.159] 7443 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412344/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412344; rev:1;) alert tcp $HOME_NET any -> [45.154.98.68] 222 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412343/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412343; rev:1;) alert tcp $HOME_NET any -> [45.143.166.102] 443 (msg:"ThreatFox pupy botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412342/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412342; rev:1;) alert tcp $HOME_NET any -> [45.144.136.36] 1099 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412341/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412341; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 75%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/devil/pws/fre.php"; depth:18; nocase; http.host; content:"rottot.shop"; depth:11; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412331/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412331; rev:1;) alert tcp $HOME_NET any -> [104.156.238.213] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412325/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412325; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 75%)"; dns_query; content:"certs.ltd"; depth:9; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412324/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412324; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"physical-assessing.gl.at.ply.gg"; depth:31; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412322/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412322; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"gamingzone90-25909.portmap.io"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412323/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412323; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sabaf-38910.portmap.host"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412320/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412320; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"twentyfivev.crabdance.com"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412321/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412321; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"service.bentleyalumni.com"; depth:25; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412318/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412318; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"sigmagyattohio69420-30849.portmap.host"; depth:38; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412319/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412319; rev:1;) alert tcp $HOME_NET any -> [147.185.221.25] 57276 (msg:"ThreatFox Quasar RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412315/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412315; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"wexodi1642-33696.portmap.host"; depth:29; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412316/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412316; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"cachedump.cachnetdotcom.com"; depth:27; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412317/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412317; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"apiexplorerzone.com"; depth:19; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412312/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412312; rev:1;) alert tcp $HOME_NET any -> [86.92.48.225] 4782 (msg:"ThreatFox Quasar RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412313/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412313; rev:1;) alert tcp $HOME_NET any -> [85.192.29.60] 5850 (msg:"ThreatFox Quasar RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412314/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412314; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.gesom.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412296/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.gesom.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412308/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412308; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"twntdd20vt.top"; depth:14; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412311/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412311; rev:1;) alert tcp $HOME_NET any -> [34.58.66.17] 4483 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412309/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412309; rev:1;) alert tcp $HOME_NET any -> [206.238.220.237] 4449 (msg:"ThreatFox AsyncRAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412310/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412310; rev:1;) alert tcp $HOME_NET any -> [134.122.128.37] 7000 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412302/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412302; rev:1;) alert tcp $HOME_NET any -> [154.12.16.122] 45682 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412303/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412303; rev:1;) alert tcp $HOME_NET any -> [172.245.135.145] 7090 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412304/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412304; rev:1;) alert tcp $HOME_NET any -> [185.241.208.215] 7000 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412305/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412305; rev:1;) alert tcp $HOME_NET any -> [198.12.127.183] 2020 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412306/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412306; rev:1;) alert tcp $HOME_NET any -> [213.142.148.34] 3162 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412307/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412307; rev:1;) alert tcp $HOME_NET any -> [38.69.15.119] 7000 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412297/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412297; rev:1;) alert tcp $HOME_NET any -> [45.88.91.186] 1000 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412298/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412298; rev:1;) alert tcp $HOME_NET any -> [45.141.26.59] 7000 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412299/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412299; rev:1;) alert tcp $HOME_NET any -> [93.127.132.136] 10003 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412300/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412300; rev:1;) alert tcp $HOME_NET any -> [101.99.94.250] 7000 (msg:"ThreatFox XWorm botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412301/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412301; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.ducar.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412294/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.ducar.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412295/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"qfreshidea.click"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412287/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412287; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"urbanaodes.click"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412289/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412289; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"uniquemexperiences.cyou"; depth:23; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412290/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412290; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"insrpiringcommunity.click"; depth:25; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412291/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412291; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"bwrightfuture.cyou"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412292/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"spuriotis.click"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412293/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"smartsjolutions.cyou"; depth:20; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412286/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412286; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"uxrbanescape.cyou"; depth:17; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412288/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412288; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.dyfut.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412284/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412284; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"analysiserjzy.click"; depth:19; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412285/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412285; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.dyfut.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412283/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412283; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.vizam.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412280/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412280; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.vizam.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412281/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412281; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"dfreamwave.cyou"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412282/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412282; rev:1;) alert tcp $HOME_NET any -> [194.59.30.80] 5930 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412279/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412279; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.kakif.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412275/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412275; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.kakif.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412278/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412278; rev:1;) alert tcp $HOME_NET any -> [31.192.232.25] 443 (msg:"ThreatFox DanaBot botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412277/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412277; rev:1;) alert tcp $HOME_NET any -> [193.3.19.136] 8080 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412276/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412276; rev:1;) alert tcp $HOME_NET any -> [15.235.197.180] 443 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412273/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412273; rev:1;) alert tcp $HOME_NET any -> [15.235.197.180] 8443 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412274/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412274; rev:1;) alert tcp $HOME_NET any -> [147.45.178.44] 443 (msg:"ThreatFox Eye Pyramid botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412272/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412272; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.givoh.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412270/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412270; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.givoh.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412271/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412271; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.jabyk.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412268/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412268; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.jabyk.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412269/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412269; rev:1;) alert tcp $HOME_NET any -> [120.46.28.4] 8889 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412205/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412205; rev:1;) alert tcp $HOME_NET any -> [43.143.123.40] 11111 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412204/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412204; rev:1;) alert tcp $HOME_NET any -> [43.133.36.25] 8083 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412206/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412206; rev:1;) alert tcp $HOME_NET any -> [124.221.5.207] 1444 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412208/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412208; rev:1;) alert tcp $HOME_NET any -> [106.14.69.133] 8999 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412207/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412207; rev:1;) alert tcp $HOME_NET any -> [156.224.19.17] 4444 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412209/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412209; rev:1;) alert tcp $HOME_NET any -> [20.189.117.246] 1132 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412210/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412210; rev:1;) alert tcp $HOME_NET any -> [54.83.104.93] 1433 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412211/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412211; rev:1;) alert tcp $HOME_NET any -> [47.109.90.134] 88 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412212/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412212; rev:1;) alert tcp $HOME_NET any -> [101.35.235.124] 4444 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412213/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412213; rev:1;) alert tcp $HOME_NET any -> [8.140.242.49] 7778 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412215/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412215; rev:1;) alert tcp $HOME_NET any -> [47.109.178.54] 2222 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412217/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412217; rev:1;) alert tcp $HOME_NET any -> [124.71.164.7] 4433 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412218/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412218; rev:1;) alert tcp $HOME_NET any -> [103.117.120.68] 13000 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412214/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412214; rev:1;) alert tcp $HOME_NET any -> [14.29.160.181] 10080 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412216/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412216; rev:1;) alert tcp $HOME_NET any -> [124.71.164.7] 5001 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412219/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412219; rev:1;) alert tcp $HOME_NET any -> [83.229.122.83] 801 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412221/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412221; rev:1;) alert tcp $HOME_NET any -> [47.120.46.210] 81 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412222/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412222; rev:1;) alert tcp $HOME_NET any -> [82.156.0.140] 9900 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412220/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412220; rev:1;) alert tcp $HOME_NET any -> [42.192.195.221] 65222 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412223/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412223; rev:1;) alert tcp $HOME_NET any -> [101.43.46.181] 7799 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412224/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412224; rev:1;) alert tcp $HOME_NET any -> [152.136.159.25] 4455 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412225/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412225; rev:1;) alert tcp $HOME_NET any -> [121.43.227.196] 88 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412226/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412226; rev:1;) alert tcp $HOME_NET any -> [47.113.217.92] 28888 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412227/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412227; rev:1;) alert tcp $HOME_NET any -> [47.83.218.121] 81 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412228/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412228; rev:1;) alert tcp $HOME_NET any -> [142.171.32.77] 22701 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412229/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412229; rev:1;) alert tcp $HOME_NET any -> [154.204.56.71] 1111 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412230/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412230; rev:1;) alert tcp $HOME_NET any -> [49.234.38.224] 81 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412231/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412231; rev:1;) alert tcp $HOME_NET any -> [111.231.144.159] 4444 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412232/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412232; rev:1;) alert tcp $HOME_NET any -> [189.1.225.221] 880 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412233/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412233; rev:1;) alert tcp $HOME_NET any -> [43.143.114.43] 8099 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412234/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412234; rev:1;) alert tcp $HOME_NET any -> [116.205.98.214] 8676 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412235/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412235; rev:1;) alert tcp $HOME_NET any -> [8.154.18.17] 12356 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412236/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412236; rev:1;) alert tcp $HOME_NET any -> [47.109.178.54] 9999 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412237/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412237; rev:1;) alert tcp $HOME_NET any -> [47.99.52.248] 8888 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412238/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412238; rev:1;) alert tcp $HOME_NET any -> [47.237.86.35] 8880 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412239/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412239; rev:1;) alert tcp $HOME_NET any -> [95.182.98.179] 8080 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412240/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412240; rev:1;) alert tcp $HOME_NET any -> [117.50.178.197] 57982 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412241/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412241; rev:1;) alert tcp $HOME_NET any -> [45.192.96.63] 6003 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412242/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412242; rev:1;) alert tcp $HOME_NET any -> [45.192.96.63] 6005 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412243/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412243; rev:1;) alert tcp $HOME_NET any -> [101.43.166.60] 5555 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412244/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412244; rev:1;) alert tcp $HOME_NET any -> [148.135.23.194] 8899 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412245/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412245; rev:1;) alert tcp $HOME_NET any -> [106.52.37.207] 2233 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412246/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412246; rev:1;) alert tcp $HOME_NET any -> [101.35.228.105] 11443 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412247/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412247; rev:1;) alert tcp $HOME_NET any -> [8.130.132.210] 7777 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412248/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412248; rev:1;) alert tcp $HOME_NET any -> [39.100.64.169] 8081 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412249/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412249; rev:1;) alert tcp $HOME_NET any -> [101.35.45.108] 50001 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412250/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412250; rev:1;) alert tcp $HOME_NET any -> [150.158.33.10] 50003 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412251/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412251; rev:1;) alert tcp $HOME_NET any -> [47.109.201.173] 8888 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412252/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412252; rev:1;) alert tcp $HOME_NET any -> [116.205.98.214] 81 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412253/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412253; rev:1;) alert tcp $HOME_NET any -> [124.222.48.227] 1111 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412254/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412254; rev:1;) alert tcp $HOME_NET any -> [121.43.131.0] 8888 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412255/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412255; rev:1;) alert tcp $HOME_NET any -> [91.92.251.104] 8080 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412256/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412256; rev:1;) alert tcp $HOME_NET any -> [1.117.60.10] 5000 (msg:"ThreatFox Cobalt Strike payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412257/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412257; rev:1;) alert tcp $HOME_NET any -> [185.156.110.13] 80 (msg:"ThreatFox Stealc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412267/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412267; rev:1;) alert tcp $HOME_NET any -> [102.100.55.52] 443 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412266/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412266; rev:1;) alert tcp $HOME_NET any -> [176.65.142.132] 4449 (msg:"ThreatFox Venom RAT botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412265/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412265; rev:1;) alert tcp $HOME_NET any -> [23.227.203.225] 10443 (msg:"ThreatFox Havoc botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412263/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412263; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 100%)"; dns_query; content:"ec2-34-229-143-231.compute-1.amazonaws.com"; depth:42; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412264/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412264; rev:1;) alert tcp $HOME_NET any -> [194.26.192.33] 80 (msg:"ThreatFox Hook botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412262/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412262; rev:1;) alert tcp $HOME_NET any -> [196.251.118.76] 8888 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412261/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412261; rev:1;) alert tcp $HOME_NET any -> [185.157.162.168] 1994 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412260/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412260; rev:1;) alert tcp $HOME_NET any -> [193.23.3.29] 8888 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412259/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412259; rev:1;) alert tcp $HOME_NET any -> [194.163.180.87] 808 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412258/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412258; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.mepyw.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412189/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412189; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.mepyw.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412195/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412195; rev:1;) alert tcp $HOME_NET any -> [120.53.238.54] 81 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412203/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412203; rev:1;) alert tcp $HOME_NET any -> [47.254.50.106] 8080 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412202/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412202; rev:1;) alert tcp $HOME_NET any -> [192.144.227.177] 9090 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412201/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412201; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"65.109.243.114"; depth:14; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412198/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412198; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"95.217.27.120"; depth:13; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412199/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412199; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"webdisk.lodrat.org"; depth:18; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412200/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412200; rev:1;) alert tcp $HOME_NET any -> [65.109.243.114] 443 (msg:"ThreatFox Vidar botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412196/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412196; rev:1;) alert tcp $HOME_NET any -> [95.217.27.120] 443 (msg:"ThreatFox Vidar botnet C2 traffic (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412197/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412197; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/prokllumexp"; depth:12; nocase; http.host; content:"t.me"; depth:4; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412194/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412194; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"resource-intensity.gl.at.ply.gg"; depth:31; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412193/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412193; rev:1;) alert tcp $HOME_NET any -> [65.109.115.25] 5552 (msg:"ThreatFox NjRAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412192/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412192; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (domain - confidence level: 50%)"; dns_query; content:"videos-flux.gl.at.ply.gg"; depth:24; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412191/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412191; rev:1;) alert tcp $HOME_NET any -> [147.185.221.26] 2935 (msg:"ThreatFox DCRat botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412190/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412190; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.zelez.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412183/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412183; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/"; depth:1; nocase; http.host; content:"196.251.112.193"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412188/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412188; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"happyfoasis.cyou"; depth:16; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412187/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412187; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 50%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/api"; depth:4; nocase; http.host; content:"dfreamwave.cyou"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412186/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412186; rev:1;) alert tcp $HOME_NET any -> [185.125.50.87] 443 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412185/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412185; rev:1;) alert tcp $HOME_NET any -> [122.51.75.246] 666 (msg:"ThreatFox Cobalt Strike botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412184/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412184; rev:1;) alert tcp $HOME_NET any -> [61.3.110.39] 57788 (msg:"ThreatFox Mozi botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412182/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412182; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.zelez.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412170/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412170; rev:1;) alert tcp $HOME_NET any -> [59.56.110.231] 9088 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412180/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412180; rev:1;) alert tcp $HOME_NET any -> [47.129.179.230] 5938 (msg:"ThreatFox NetSupportManager RAT botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412181/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412181; rev:1;) alert tcp $HOME_NET any -> [123.57.2.124] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412178/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412178; rev:1;) alert tcp $HOME_NET any -> [185.195.106.81] 31337 (msg:"ThreatFox Sliver botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412179/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412179; rev:1;) alert tcp $HOME_NET any -> [181.50.73.64] 37722 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412175/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412175; rev:1;) alert tcp $HOME_NET any -> [181.50.73.64] 50322 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412176/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412176; rev:1;) alert tcp $HOME_NET any -> [181.50.73.64] 50422 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412177/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412177; rev:1;) alert tcp $HOME_NET any -> [181.50.73.64] 54122 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412172/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412172; rev:1;) alert tcp $HOME_NET any -> [188.166.25.37] 3333 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412173/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412173; rev:1;) alert tcp $HOME_NET any -> [181.50.73.64] 43422 (msg:"ThreatFox Unknown malware botnet C2 traffic (ip:port - confidence level: 50%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412174/; target:src_ip; metadata: confidence_level 50, first_seen 2025_02_14; classtype:trojan-activity; sid:91412174; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox botnet C2 traffic (url - confidence level: 75%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hl341/index.php"; depth:16; nocase; http.host; content:"gdm5.icu"; depth:8; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412171/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412171; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (url - confidence level: 100%)"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gkcxv.google"; depth:13; nocase; http.host; content:"check.tonev.icu"; depth:15; isdataat:!1,relative; reference:url, threatfox.abuse.ch/ioc/1412168/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412168; rev:1;) alert tcp $HOME_NET any -> [37.120.208.40] 56379 (msg:"ThreatFox Remcos botnet C2 traffic (ip:port - confidence level: 75%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412169/; target:src_ip; metadata: confidence_level 75, first_seen 2025_02_14; classtype:trojan-activity; sid:91412169; rev:1;) alert dns $HOME_NET any -> $EXTERNAL_NET any (msg:"ThreatFox payload delivery (domain - confidence level: 100%)"; dns_query; content:"check.tonev.icu"; depth:15; fast_pattern; isdataat:!1,relative; nocase; reference:url, threatfox.abuse.ch/ioc/1412167/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412167; rev:1;) alert tcp $HOME_NET any -> [14.155.188.14] 60552 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411969/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411969; rev:1;) alert tcp $HOME_NET any -> [117.253.107.77] 57419 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411970/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411970; rev:1;) alert tcp $HOME_NET any -> [117.202.65.36] 39376 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411971/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411971; rev:1;) alert tcp $HOME_NET any -> [61.3.208.200] 39691 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411972/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411972; rev:1;) alert tcp $HOME_NET any -> [115.56.159.197] 48902 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411974/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411974; rev:1;) alert tcp $HOME_NET any -> [175.165.85.242] 46873 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411973/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411973; rev:1;) alert tcp $HOME_NET any -> [115.55.94.214] 50119 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411975/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411975; rev:1;) alert tcp $HOME_NET any -> [115.58.83.170] 34050 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411976/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411976; rev:1;) alert tcp $HOME_NET any -> [123.12.10.11] 41620 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411977/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411977; rev:1;) alert tcp $HOME_NET any -> [123.4.44.42] 44782 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411978/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411978; rev:1;) alert tcp $HOME_NET any -> [222.140.158.251] 49005 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411980/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411980; rev:1;) alert tcp $HOME_NET any -> [217.208.204.56] 58447 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411979/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411979; rev:1;) alert tcp $HOME_NET any -> [27.207.91.1] 54720 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411981/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411981; rev:1;) alert tcp $HOME_NET any -> [117.255.98.244] 39330 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411982/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411982; rev:1;) alert tcp $HOME_NET any -> [182.113.201.173] 55203 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411983/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411983; rev:1;) alert tcp $HOME_NET any -> [113.238.77.36] 44848 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411984/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411984; rev:1;) alert tcp $HOME_NET any -> [59.54.88.94] 52777 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411985/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411985; rev:1;) alert tcp $HOME_NET any -> [42.227.34.15] 48586 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411986/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411986; rev:1;) alert tcp $HOME_NET any -> [61.0.144.92] 38397 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411987/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411987; rev:1;) alert tcp $HOME_NET any -> [113.92.223.14] 52517 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411988/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411988; rev:1;) alert tcp $HOME_NET any -> [59.182.141.128] 44016 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411989/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411989; rev:1;) alert tcp $HOME_NET any -> [61.53.140.37] 55039 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411990/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411990; rev:1;) alert tcp $HOME_NET any -> [117.219.42.125] 46735 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411992/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411992; rev:1;) alert tcp $HOME_NET any -> [120.61.24.196] 49076 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411991/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411991; rev:1;) alert tcp $HOME_NET any -> [59.95.83.73] 43363 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411993/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411993; rev:1;) alert tcp $HOME_NET any -> [182.118.159.138] 33519 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411994/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411994; rev:1;) alert tcp $HOME_NET any -> [182.127.132.174] 36948 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411995/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411995; rev:1;) alert tcp $HOME_NET any -> [182.120.49.245] 49337 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411996/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411996; rev:1;) alert tcp $HOME_NET any -> [117.253.101.22] 38568 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411997/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411997; rev:1;) alert tcp $HOME_NET any -> [117.254.60.135] 53159 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411999/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411999; rev:1;) alert tcp $HOME_NET any -> [58.47.43.12] 36940 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1411998/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91411998; rev:1;) alert tcp $HOME_NET any -> [120.56.5.189] 42658 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412000/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412000; rev:1;) alert tcp $HOME_NET any -> [117.192.38.155] 33392 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412001/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412001; rev:1;) alert tcp $HOME_NET any -> [115.61.97.186] 55839 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412002/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412002; rev:1;) alert tcp $HOME_NET any -> [36.100.18.17] 47929 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412003/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412003; rev:1;) alert tcp $HOME_NET any -> [120.61.239.166] 45010 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412004/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412004; rev:1;) alert tcp $HOME_NET any -> [42.54.196.157] 60860 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412006/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412006; rev:1;) alert tcp $HOME_NET any -> [117.204.164.49] 49599 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412005/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412005; rev:1;) alert tcp $HOME_NET any -> [223.11.57.128] 45732 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412007/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412007; rev:1;) alert tcp $HOME_NET any -> [59.182.126.26] 54200 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412008/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412008; rev:1;) alert tcp $HOME_NET any -> [42.238.141.143] 54380 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412009/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412009; rev:1;) alert tcp $HOME_NET any -> [115.52.4.200] 38212 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412010/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412010; rev:1;) alert tcp $HOME_NET any -> [117.252.171.152] 39287 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412011/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412011; rev:1;) alert tcp $HOME_NET any -> [36.97.146.17] 42561 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412012/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412012; rev:1;) alert tcp $HOME_NET any -> [175.167.87.156] 56721 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412013/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412013; rev:1;) alert tcp $HOME_NET any -> [78.189.35.154] 60732 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412014/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412014; rev:1;) alert tcp $HOME_NET any -> [117.211.252.219] 37949 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412015/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412015; rev:1;) alert tcp $HOME_NET any -> [112.248.111.119] 36350 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412016/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412016; rev:1;) alert tcp $HOME_NET any -> [189.174.81.167] 34577 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412017/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412017; rev:1;) alert tcp $HOME_NET any -> [83.48.200.74] 34174 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412018/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412018; rev:1;) alert tcp $HOME_NET any -> [117.213.118.134] 46045 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412019/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412019; rev:1;) alert tcp $HOME_NET any -> [61.52.229.192] 44320 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412020/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412020; rev:1;) alert tcp $HOME_NET any -> [61.3.172.163] 50809 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412021/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412021; rev:1;) alert tcp $HOME_NET any -> [59.89.25.168] 58462 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412022/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412022; rev:1;) alert tcp $HOME_NET any -> [117.209.6.187] 55387 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412023/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412023; rev:1;) alert tcp $HOME_NET any -> [115.51.125.28] 45283 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412024/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412024; rev:1;) alert tcp $HOME_NET any -> [117.209.8.4] 43696 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412025/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412025; rev:1;) alert tcp $HOME_NET any -> [175.165.85.9] 59780 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412026/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412026; rev:1;) alert tcp $HOME_NET any -> [59.88.251.39] 50463 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412027/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412027; rev:1;) alert tcp $HOME_NET any -> [59.97.116.251] 49522 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412028/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412028; rev:1;) alert tcp $HOME_NET any -> [117.209.3.142] 39989 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412029/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412029; rev:1;) alert tcp $HOME_NET any -> [182.117.70.102] 48561 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412030/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412030; rev:1;) alert tcp $HOME_NET any -> [117.196.174.241] 44590 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412031/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412031; rev:1;) alert tcp $HOME_NET any -> [222.241.48.205] 39319 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412048/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412048; rev:1;) alert tcp $HOME_NET any -> [27.215.53.150] 51484 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412044/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412044; rev:1;) alert tcp $HOME_NET any -> [60.23.238.191] 40709 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412046/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412046; rev:1;) alert tcp $HOME_NET any -> [117.209.92.77] 46342 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412047/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412047; rev:1;) alert tcp $HOME_NET any -> [123.9.218.164] 44456 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412043/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412043; rev:1;) alert tcp $HOME_NET any -> [223.10.11.208] 48203 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412045/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412045; rev:1;) alert tcp $HOME_NET any -> [59.183.32.14] 49220 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412040/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412040; rev:1;) alert tcp $HOME_NET any -> [42.224.249.106] 41101 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412041/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412041; rev:1;) alert tcp $HOME_NET any -> [117.209.25.46] 48771 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412042/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412042; rev:1;) alert tcp $HOME_NET any -> [59.88.178.88] 36198 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412038/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412038; rev:1;) alert tcp $HOME_NET any -> [119.179.222.75] 35778 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412039/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412039; rev:1;) alert tcp $HOME_NET any -> [78.187.17.22] 38637 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412034/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412034; rev:1;) alert tcp $HOME_NET any -> [61.3.103.72] 51543 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412035/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412035; rev:1;) alert tcp $HOME_NET any -> [59.97.119.33] 59147 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412036/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412036; rev:1;) alert tcp $HOME_NET any -> [61.137.175.45] 39874 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412037/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412037; rev:1;) alert tcp $HOME_NET any -> [115.55.193.94] 34009 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412033/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412033; rev:1;) alert tcp $HOME_NET any -> [175.175.99.41] 50780 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412032/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412032; rev:1;) alert tcp $HOME_NET any -> [176.36.148.87] 45781 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412049/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412049; rev:1;) alert tcp $HOME_NET any -> [117.242.233.237] 36798 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412050/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412050; rev:1;) alert tcp $HOME_NET any -> [113.221.46.223] 55136 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412051/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412051; rev:1;) alert tcp $HOME_NET any -> [59.99.215.123] 45986 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412052/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412052; rev:1;) alert tcp $HOME_NET any -> [59.89.239.173] 36150 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412053/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412053; rev:1;) alert tcp $HOME_NET any -> [106.56.138.202] 48749 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412054/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412054; rev:1;) alert tcp $HOME_NET any -> [180.119.109.53] 36724 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412055/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412055; rev:1;) alert tcp $HOME_NET any -> [175.167.103.224] 36316 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412056/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412056; rev:1;) alert tcp $HOME_NET any -> [119.115.244.219] 37800 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412057/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412057; rev:1;) alert tcp $HOME_NET any -> [59.94.44.209] 46006 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412058/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412058; rev:1;) alert tcp $HOME_NET any -> [120.61.19.167] 59009 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412059/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412059; rev:1;) alert tcp $HOME_NET any -> [222.138.110.180] 56898 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412060/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412060; rev:1;) alert tcp $HOME_NET any -> [60.19.7.201] 39589 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412061/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412061; rev:1;) alert tcp $HOME_NET any -> [61.53.93.196] 55428 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412062/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412062; rev:1;) alert tcp $HOME_NET any -> [221.15.17.107] 56362 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412063/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412063; rev:1;) alert tcp $HOME_NET any -> [222.136.153.49] 37336 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412064/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412064; rev:1;) alert tcp $HOME_NET any -> [61.54.206.124] 36242 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412065/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412065; rev:1;) alert tcp $HOME_NET any -> [182.114.198.97] 49346 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412066/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412066; rev:1;) alert tcp $HOME_NET any -> [123.13.100.146] 34694 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412067/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412067; rev:1;) alert tcp $HOME_NET any -> [182.53.98.8] 51939 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412068/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412068; rev:1;) alert tcp $HOME_NET any -> [117.219.95.230] 35434 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412069/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412069; rev:1;) alert tcp $HOME_NET any -> [115.55.218.128] 59100 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412070/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412070; rev:1;) alert tcp $HOME_NET any -> [59.88.1.26] 56681 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412071/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412071; rev:1;) alert tcp $HOME_NET any -> [115.59.29.86] 44835 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412072/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412072; rev:1;) alert tcp $HOME_NET any -> [117.219.38.85] 40373 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412073/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412073; rev:1;) alert tcp $HOME_NET any -> [117.198.9.121] 50702 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412074/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412074; rev:1;) alert tcp $HOME_NET any -> [117.235.125.56] 34821 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412075/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412075; rev:1;) alert tcp $HOME_NET any -> [219.157.18.92] 50458 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412076/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412076; rev:1;) alert tcp $HOME_NET any -> [59.184.253.188] 49645 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412077/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412077; rev:1;) alert tcp $HOME_NET any -> [59.184.68.24] 43986 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412078/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412078; rev:1;) alert tcp $HOME_NET any -> [178.177.200.61] 59965 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412079/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412079; rev:1;) alert tcp $HOME_NET any -> [42.229.168.116] 59094 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412080/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412080; rev:1;) alert tcp $HOME_NET any -> [182.117.108.1] 33433 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412081/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412081; rev:1;) alert tcp $HOME_NET any -> [117.209.93.126] 56189 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412082/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412082; rev:1;) alert tcp $HOME_NET any -> [188.38.3.30] 49263 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412083/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412083; rev:1;) alert tcp $HOME_NET any -> [117.209.11.133] 42279 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412084/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412084; rev:1;) alert tcp $HOME_NET any -> [117.255.180.48] 60563 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412085/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412085; rev:1;) alert tcp $HOME_NET any -> [113.0.160.113] 49910 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412086/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412086; rev:1;) alert tcp $HOME_NET any -> [117.235.98.5] 33920 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412087/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412087; rev:1;) alert tcp $HOME_NET any -> [117.235.145.183] 41693 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412088/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412088; rev:1;) alert tcp $HOME_NET any -> [117.241.178.228] 48244 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412089/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412089; rev:1;) alert tcp $HOME_NET any -> [59.88.45.23] 56107 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412090/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412090; rev:1;) alert tcp $HOME_NET any -> [61.52.50.93] 58017 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412091/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412091; rev:1;) alert tcp $HOME_NET any -> [115.52.1.50] 52982 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412092/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412092; rev:1;) alert tcp $HOME_NET any -> [42.235.187.127] 42753 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412093/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412093; rev:1;) alert tcp $HOME_NET any -> [112.248.113.107] 55163 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412094/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412094; rev:1;) alert tcp $HOME_NET any -> [177.12.94.85] 57984 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412095/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412095; rev:1;) alert tcp $HOME_NET any -> [219.155.80.144] 40272 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412097/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412097; rev:1;) alert tcp $HOME_NET any -> [117.223.0.185] 55666 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412096/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412096; rev:1;) alert tcp $HOME_NET any -> [125.46.233.44] 48478 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412098/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412098; rev:1;) alert tcp $HOME_NET any -> [175.173.163.156] 53659 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412099/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412099; rev:1;) alert tcp $HOME_NET any -> [117.211.47.205] 38103 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412100/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412100; rev:1;) alert tcp $HOME_NET any -> [220.201.40.154] 35147 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412101/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; classtype:trojan-activity; sid:91412101; rev:1;) alert tcp $HOME_NET any -> [117.221.254.202] 40116 (msg:"ThreatFox Mirai payload delivery (ip:port - confidence level: 100%)"; threshold: type limit, track by_src, seconds 60, count 1; reference:url, threatfox.abuse.ch/ioc/1412102/; target:src_ip; metadata: confidence_level 100, first_seen 2025_02_14; cl