################################################################ # abuse.ch Feodo Tracker Suricata / Snort Ruleset # # Last updated: 2022-08-12 16:25:23 UTC # # # # Terms Of Use: https://feodotracker.abuse.ch/blocklist/ # # For questions please contact feodotracker [at] abuse.ch # ################################################################ # alert tcp $HOME_NET any -> [51.178.161.32] 4643 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.178.161.32/; sid:900505003; rev:1;) alert tcp $HOME_NET any -> [46.101.90.205] 4643 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/46.101.90.205/; sid:900505046; rev:1;) alert tcp $HOME_NET any -> [142.44.247.57] 4043 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/142.44.247.57/; sid:900505384; rev:1;) alert tcp $HOME_NET any -> [37.187.115.122] 6601 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/37.187.115.122/; sid:900505528; rev:1;) alert tcp $HOME_NET any -> [121.199.35.69] 443 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/121.199.35.69/; sid:900505596; rev:1;) alert tcp $HOME_NET any -> [37.247.35.130] 6601 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/37.247.35.130/; sid:900505648; rev:1;) alert tcp $HOME_NET any -> [1.234.21.73] 6601 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/1.234.21.73/; sid:900505871; rev:1;) alert tcp $HOME_NET any -> [178.128.23.9] 4125 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/178.128.23.9/; sid:900505872; rev:1;) alert tcp $HOME_NET any -> [45.79.91.89] 9987 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/45.79.91.89/; sid:900505979; rev:1;) alert tcp $HOME_NET any -> [178.128.197.110] 4664 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/178.128.197.110/; sid:900506037; rev:1;) alert tcp $HOME_NET any -> [37.59.103.148] 4664 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/37.59.103.148/; sid:900506178; rev:1;) alert tcp $HOME_NET any -> [107.170.64.97] 9043 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/107.170.64.97/; sid:900506184; rev:1;) alert tcp $HOME_NET any -> [66.175.217.172] 13786 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/66.175.217.172/; sid:900506190; rev:1;) alert tcp $HOME_NET any -> [104.248.178.90] 4664 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/104.248.178.90/; sid:900506231; rev:1;) alert tcp $HOME_NET any -> [103.109.247.13] 10443 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/103.109.247.13/; sid:900506271; rev:1;) alert tcp $HOME_NET any -> [103.253.107.155] 7443 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/103.253.107.155/; sid:900506297; rev:1;) alert tcp $HOME_NET any -> [103.253.107.198] 7443 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/103.253.107.198/; sid:900506347; rev:1;) alert tcp $HOME_NET any -> [204.174.223.210] 9043 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/204.174.223.210/; sid:900506350; rev:1;) alert tcp $HOME_NET any -> [50.116.62.25] 8194 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/50.116.62.25/; sid:900506367; rev:1;) alert tcp $HOME_NET any -> [103.109.247.8] 10443 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/103.109.247.8/; sid:900506399; rev:1;) alert tcp $HOME_NET any -> [192.99.150.39] 7443 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/192.99.150.39/; sid:900506412; rev:1;) alert tcp $HOME_NET any -> [97.107.134.115] 10172 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/97.107.134.115/; sid:900506431; rev:1;) alert tcp $HOME_NET any -> [207.154.208.93] 6225 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/207.154.208.93/; sid:900506458; rev:1;) alert tcp $HOME_NET any -> [128.199.232.159] 6225 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/128.199.232.159/; sid:900506508; rev:1;) alert tcp $HOME_NET any -> [159.65.3.147] 6225 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/159.65.3.147/; sid:900506514; rev:1;) alert tcp $HOME_NET any -> [89.101.97.139] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/89.101.97.139/; sid:900506579; rev:1;) alert tcp $HOME_NET any -> [120.150.218.241] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/120.150.218.241/; sid:900506589; rev:1;) alert tcp $HOME_NET any -> [41.228.22.180] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/41.228.22.180/; sid:900506590; rev:1;) alert tcp $HOME_NET any -> [24.139.72.117] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/24.139.72.117/; sid:900506593; rev:1;) alert tcp $HOME_NET any -> [73.151.236.31] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/73.151.236.31/; sid:900506596; rev:1;) alert tcp $HOME_NET any -> [173.21.10.71] 2222 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/173.21.10.71/; sid:900506600; rev:1;) alert tcp $HOME_NET any -> [45.46.53.140] 2222 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/45.46.53.140/; sid:900506603; rev:1;) alert tcp $HOME_NET any -> [217.17.56.163] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/217.17.56.163/; sid:900506604; rev:1;) alert tcp $HOME_NET any -> [217.17.56.163] 2078 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/217.17.56.163/; sid:900506608; rev:1;) alert tcp $HOME_NET any -> [217.17.56.163] 465 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/217.17.56.163/; sid:900506609; rev:1;) alert tcp $HOME_NET any -> [76.25.142.196] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/76.25.142.196/; sid:900506617; rev:1;) alert tcp $HOME_NET any -> [67.165.206.193] 993 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/67.165.206.193/; sid:900506618; rev:1;) alert tcp $HOME_NET any -> [109.12.111.14] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/109.12.111.14/; sid:900506625; rev:1;) alert tcp $HOME_NET any -> [41.86.42.158] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/41.86.42.158/; sid:900506735; rev:1;) alert tcp $HOME_NET any -> [63.143.92.99] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/63.143.92.99/; sid:900506738; rev:1;) alert tcp $HOME_NET any -> [212.112.86.37] 9676 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/212.112.86.37/; sid:900506750; rev:1;) alert tcp $HOME_NET any -> [69.64.50.41] 6602 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/69.64.50.41/; sid:900506771; rev:1;) alert tcp $HOME_NET any -> [96.37.113.36] 993 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/96.37.113.36/; sid:900506787; rev:1;) alert tcp $HOME_NET any -> [38.70.253.226] 2222 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/38.70.253.226/; sid:900506828; rev:1;) alert tcp $HOME_NET any -> [207.246.112.221] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/207.246.112.221/; sid:900506865; rev:1;) alert tcp $HOME_NET any -> [103.116.178.85] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/103.116.178.85/; sid:900506903; rev:1;) alert tcp $HOME_NET any -> [93.48.80.198] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/93.48.80.198/; sid:900506907; rev:1;) alert tcp $HOME_NET any -> [117.248.109.38] 21 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/117.248.109.38/; sid:900506910; rev:1;) alert tcp $HOME_NET any -> [91.121.134.180] 10172 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/91.121.134.180/; sid:900506933; rev:1;) alert tcp $HOME_NET any -> [216.238.71.31] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/216.238.71.31/; sid:900506938; rev:1;) alert tcp $HOME_NET any -> [216.238.71.31] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/216.238.71.31/; sid:900506939; rev:1;) alert tcp $HOME_NET any -> [216.238.72.121] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/216.238.72.121/; sid:900506941; rev:1;) alert tcp $HOME_NET any -> [216.238.72.121] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/216.238.72.121/; sid:900506942; rev:1;) alert tcp $HOME_NET any -> [104.248.155.133] 443 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/104.248.155.133/; sid:900506952; rev:1;) alert tcp $HOME_NET any -> [103.74.143.53] 443 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/103.74.143.53/; sid:900506954; rev:1;) alert tcp $HOME_NET any -> [95.110.160.239] 9676 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/95.110.160.239/; sid:900507014; rev:1;) alert tcp $HOME_NET any -> [198.61.167.176] 10172 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/198.61.167.176/; sid:900507015; rev:1;) alert tcp $HOME_NET any -> [93.188.167.97] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/93.188.167.97/; sid:900507077; rev:1;) alert tcp $HOME_NET any -> [185.184.25.237] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/185.184.25.237/; sid:900507088; rev:1;) alert tcp $HOME_NET any -> [62.210.200.63] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/62.210.200.63/; sid:900507092; rev:1;) alert tcp $HOME_NET any -> [198.199.70.22] 6602 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/198.199.70.22/; sid:900507094; rev:1;) alert tcp $HOME_NET any -> [103.109.247.10] 10443 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/103.109.247.10/; sid:900507312; rev:1;) alert tcp $HOME_NET any -> [46.55.222.11] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/46.55.222.11/; sid:900507323; rev:1;) alert tcp $HOME_NET any -> [51.159.35.157] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.159.35.157/; sid:900507352; rev:1;) alert tcp $HOME_NET any -> [91.207.181.106] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/91.207.181.106/; sid:900507361; rev:1;) alert tcp $HOME_NET any -> [186.250.48.117] 443 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/186.250.48.117/; sid:900507372; rev:1;) alert tcp $HOME_NET any -> [129.232.146.250] 443 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/129.232.146.250/; sid:900507375; rev:1;) alert tcp $HOME_NET any -> [139.59.56.73] 443 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/139.59.56.73/; sid:900507479; rev:1;) alert tcp $HOME_NET any -> [144.91.122.94] 443 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/144.91.122.94/; sid:900507519; rev:1;) alert tcp $HOME_NET any -> [167.99.141.108] 4664 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/167.99.141.108/; sid:900507520; rev:1;) alert tcp $HOME_NET any -> [37.59.74.180] 593 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/37.59.74.180/; sid:900507521; rev:1;) alert tcp $HOME_NET any -> [24.178.196.158] 2222 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/24.178.196.158/; sid:900507534; rev:1;) alert tcp $HOME_NET any -> [67.209.195.198] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/67.209.195.198/; sid:900507540; rev:1;) alert tcp $HOME_NET any -> [182.191.92.203] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/182.191.92.203/; sid:900507550; rev:1;) alert tcp $HOME_NET any -> [111.125.245.116] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/111.125.245.116/; sid:900507551; rev:1;) alert tcp $HOME_NET any -> [144.91.122.100] 443 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/144.91.122.100/; sid:900507572; rev:1;) alert tcp $HOME_NET any -> [31.35.28.29] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/31.35.28.29/; sid:900507591; rev:1;) alert tcp $HOME_NET any -> [51.38.71.0] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.38.71.0/; sid:900507613; rev:1;) alert tcp $HOME_NET any -> [69.14.172.24] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/69.14.172.24/; sid:900507623; rev:1;) alert tcp $HOME_NET any -> [91.121.146.47] 10443 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/91.121.146.47/; sid:900507656; rev:1;) alert tcp $HOME_NET any -> [103.9.36.172] 443 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/103.9.36.172/; sid:900507658; rev:1;) alert tcp $HOME_NET any -> [139.99.30.176] 443 (msg:"Feodo Tracker: potential Dridex CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/139.99.30.176/; sid:900507665; rev:1;) alert tcp $HOME_NET any -> [131.100.24.231] 80 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/131.100.24.231/; sid:900507670; rev:1;) alert tcp $HOME_NET any -> [144.217.88.125] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/144.217.88.125/; sid:900507687; rev:1;) alert tcp $HOME_NET any -> [62.141.45.103] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/62.141.45.103/; sid:900507792; rev:1;) alert tcp $HOME_NET any -> [159.65.163.220] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/159.65.163.220/; sid:900507793; rev:1;) alert tcp $HOME_NET any -> [139.196.72.155] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/139.196.72.155/; sid:900507799; rev:1;) alert tcp $HOME_NET any -> [177.39.156.177] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/177.39.156.177/; sid:900507814; rev:1;) alert tcp $HOME_NET any -> [180.250.21.2] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/180.250.21.2/; sid:900507857; rev:1;) alert tcp $HOME_NET any -> [142.93.76.76] 7080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/142.93.76.76/; sid:900507858; rev:1;) alert tcp $HOME_NET any -> [185.184.25.78] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/185.184.25.78/; sid:900507864; rev:1;) alert tcp $HOME_NET any -> [54.37.106.167] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/54.37.106.167/; sid:900507865; rev:1;) alert tcp $HOME_NET any -> [172.105.115.71] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/172.105.115.71/; sid:900507866; rev:1;) alert tcp $HOME_NET any -> [66.230.104.103] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/66.230.104.103/; sid:900507940; rev:1;) alert tcp $HOME_NET any -> [217.128.122.65] 2222 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/217.128.122.65/; sid:900507952; rev:1;) alert tcp $HOME_NET any -> [47.180.172.159] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/47.180.172.159/; sid:900507956; rev:1;) alert tcp $HOME_NET any -> [208.107.221.224] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/208.107.221.224/; sid:900507965; rev:1;) alert tcp $HOME_NET any -> [173.174.216.62] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/173.174.216.62/; sid:900507971; rev:1;) alert tcp $HOME_NET any -> [82.41.63.217] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/82.41.63.217/; sid:900507979; rev:1;) alert tcp $HOME_NET any -> [144.202.2.175] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/144.202.2.175/; sid:900507990; rev:1;) alert tcp $HOME_NET any -> [144.202.2.175] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/144.202.2.175/; sid:900507993; rev:1;) alert tcp $HOME_NET any -> [47.23.89.60] 993 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/47.23.89.60/; sid:900507995; rev:1;) alert tcp $HOME_NET any -> [196.203.37.215] 80 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/196.203.37.215/; sid:900508012; rev:1;) alert tcp $HOME_NET any -> [159.65.253.201] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/159.65.253.201/; sid:900508015; rev:1;) alert tcp $HOME_NET any -> [150.95.20.209] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/150.95.20.209/; sid:900508016; rev:1;) alert tcp $HOME_NET any -> [103.44.138.22] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/103.44.138.22/; sid:900508017; rev:1;) alert tcp $HOME_NET any -> [68.183.62.61] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/68.183.62.61/; sid:900508023; rev:1;) alert tcp $HOME_NET any -> [136.243.32.168] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/136.243.32.168/; sid:900508032; rev:1;) alert tcp $HOME_NET any -> [24.55.67.176] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/24.55.67.176/; sid:900508087; rev:1;) alert tcp $HOME_NET any -> [162.244.80.68] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/162.244.80.68/; sid:900508090; rev:1;) alert tcp $HOME_NET any -> [209.126.98.206] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/209.126.98.206/; sid:900508113; rev:1;) alert tcp $HOME_NET any -> [51.254.140.238] 7080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.254.140.238/; sid:900508120; rev:1;) alert tcp $HOME_NET any -> [103.75.201.2] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/103.75.201.2/; sid:900508121; rev:1;) alert tcp $HOME_NET any -> [172.114.160.81] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/172.114.160.81/; sid:900508126; rev:1;) alert tcp $HOME_NET any -> [70.46.220.114] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/70.46.220.114/; sid:900508132; rev:1;) alert tcp $HOME_NET any -> [217.79.180.211] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/217.79.180.211/; sid:900508181; rev:1;) alert tcp $HOME_NET any -> [45.63.1.12] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/45.63.1.12/; sid:900508185; rev:1;) alert tcp $HOME_NET any -> [149.28.238.199] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/149.28.238.199/; sid:900508186; rev:1;) alert tcp $HOME_NET any -> [45.76.167.26] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/45.76.167.26/; sid:900508187; rev:1;) alert tcp $HOME_NET any -> [144.202.3.39] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/144.202.3.39/; sid:900508188; rev:1;) alert tcp $HOME_NET any -> [144.202.3.39] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/144.202.3.39/; sid:900508189; rev:1;) alert tcp $HOME_NET any -> [149.28.238.199] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/149.28.238.199/; sid:900508190; rev:1;) alert tcp $HOME_NET any -> [45.63.1.12] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/45.63.1.12/; sid:900508191; rev:1;) alert tcp $HOME_NET any -> [45.76.167.26] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/45.76.167.26/; sid:900508192; rev:1;) alert tcp $HOME_NET any -> [140.82.63.183] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/140.82.63.183/; sid:900508193; rev:1;) alert tcp $HOME_NET any -> [140.82.63.183] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/140.82.63.183/; sid:900508194; rev:1;) alert tcp $HOME_NET any -> [5.32.41.45] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/5.32.41.45/; sid:900508214; rev:1;) alert tcp $HOME_NET any -> [167.86.122.137] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/167.86.122.137/; sid:900508235; rev:1;) alert tcp $HOME_NET any -> [82.165.145.100] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/82.165.145.100/; sid:900508237; rev:1;) alert tcp $HOME_NET any -> [148.64.96.100] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/148.64.96.100/; sid:900508263; rev:1;) alert tcp $HOME_NET any -> [119.193.124.41] 7080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/119.193.124.41/; sid:900508284; rev:1;) alert tcp $HOME_NET any -> [165.22.61.235] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/165.22.61.235/; sid:900508285; rev:1;) alert tcp $HOME_NET any -> [116.125.120.88] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/116.125.120.88/; sid:900508291; rev:1;) alert tcp $HOME_NET any -> [172.115.177.204] 2222 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/172.115.177.204/; sid:900508297; rev:1;) alert tcp $HOME_NET any -> [174.69.215.101] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/174.69.215.101/; sid:900508298; rev:1;) alert tcp $HOME_NET any -> [47.145.130.171] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/47.145.130.171/; sid:900508309; rev:1;) alert tcp $HOME_NET any -> [188.166.229.148] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/188.166.229.148/; sid:900508320; rev:1;) alert tcp $HOME_NET any -> [40.134.246.185] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/40.134.246.185/; sid:900508333; rev:1;) alert tcp $HOME_NET any -> [165.22.246.219] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/165.22.246.219/; sid:900508358; rev:1;) alert tcp $HOME_NET any -> [179.158.105.44] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/179.158.105.44/; sid:900508419; rev:1;) alert tcp $HOME_NET any -> [190.252.242.69] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/190.252.242.69/; sid:900508486; rev:1;) alert tcp $HOME_NET any -> [32.221.224.140] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/32.221.224.140/; sid:900508501; rev:1;) alert tcp $HOME_NET any -> [46.107.48.202] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/46.107.48.202/; sid:900508530; rev:1;) alert tcp $HOME_NET any -> [37.34.253.233] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/37.34.253.233/; sid:900508549; rev:1;) alert tcp $HOME_NET any -> [149.56.131.28] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/149.56.131.28/; sid:900508556; rev:1;) alert tcp $HOME_NET any -> [103.246.242.202] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/103.246.242.202/; sid:900508600; rev:1;) alert tcp $HOME_NET any -> [103.133.11.10] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/103.133.11.10/; sid:900508620; rev:1;) alert tcp $HOME_NET any -> [94.23.45.86] 4143 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/94.23.45.86/; sid:900508644; rev:1;) alert tcp $HOME_NET any -> [49.231.16.102] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/49.231.16.102/; sid:900508656; rev:1;) alert tcp $HOME_NET any -> [138.197.147.101] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/138.197.147.101/; sid:900508662; rev:1;) alert tcp $HOME_NET any -> [139.59.44.48] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/139.59.44.48/; sid:900508706; rev:1;) alert tcp $HOME_NET any -> [104.34.212.7] 32103 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/104.34.212.7/; sid:900508714; rev:1;) alert tcp $HOME_NET any -> [178.62.112.199] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/178.62.112.199/; sid:900508734; rev:1;) alert tcp $HOME_NET any -> [186.90.153.162] 2222 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/186.90.153.162/; sid:900508792; rev:1;) alert tcp $HOME_NET any -> [150.95.66.124] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/150.95.66.124/; sid:900508809; rev:1;) alert tcp $HOME_NET any -> [158.69.222.101] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/158.69.222.101/; sid:900508824; rev:1;) alert tcp $HOME_NET any -> [188.225.32.231] 4143 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/188.225.32.231/; sid:900508829; rev:1;) alert tcp $HOME_NET any -> [45.226.53.34] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/45.226.53.34/; sid:900508841; rev:1;) alert tcp $HOME_NET any -> [134.122.119.23] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/134.122.119.23/; sid:900508862; rev:1;) alert tcp $HOME_NET any -> [188.166.217.40] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/188.166.217.40/; sid:900508899; rev:1;) alert tcp $HOME_NET any -> [51.91.142.26] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.91.142.26/; sid:900508904; rev:1;) alert tcp $HOME_NET any -> [165.227.166.238] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/165.227.166.238/; sid:900508905; rev:1;) alert tcp $HOME_NET any -> [167.172.248.70] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/167.172.248.70/; sid:900508906; rev:1;) alert tcp $HOME_NET any -> [173.82.82.196] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/173.82.82.196/; sid:900508915; rev:1;) alert tcp $HOME_NET any -> [159.89.202.34] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/159.89.202.34/; sid:900508916; rev:1;) alert tcp $HOME_NET any -> [74.14.5.179] 2222 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/74.14.5.179/; sid:900508925; rev:1;) alert tcp $HOME_NET any -> [161.97.91.52] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/161.97.91.52/; sid:900508946; rev:1;) alert tcp $HOME_NET any -> [51.83.253.244] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.83.253.244/; sid:900508980; rev:1;) alert tcp $HOME_NET any -> [54.38.137.18] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/54.38.137.18/; sid:900508995; rev:1;) alert tcp $HOME_NET any -> [145.239.30.26] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/145.239.30.26/; sid:900508999; rev:1;) alert tcp $HOME_NET any -> [54.38.138.141] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/54.38.138.141/; sid:900509000; rev:1;) alert tcp $HOME_NET any -> [54.38.139.20] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/54.38.139.20/; sid:900509011; rev:1;) alert tcp $HOME_NET any -> [145.239.29.119] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/145.239.29.119/; sid:900509018; rev:1;) alert tcp $HOME_NET any -> [72.252.157.93] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/72.252.157.93/; sid:900509036; rev:1;) alert tcp $HOME_NET any -> [72.252.157.93] 990 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/72.252.157.93/; sid:900509037; rev:1;) alert tcp $HOME_NET any -> [72.252.157.93] 993 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/72.252.157.93/; sid:900509038; rev:1;) alert tcp $HOME_NET any -> [54.38.136.187] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/54.38.136.187/; sid:900509044; rev:1;) alert tcp $HOME_NET any -> [146.19.173.202] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/146.19.173.202/; sid:900509056; rev:1;) alert tcp $HOME_NET any -> [51.75.62.15] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.75.62.15/; sid:900509064; rev:1;) alert tcp $HOME_NET any -> [51.75.62.99] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.75.62.99/; sid:900509077; rev:1;) alert tcp $HOME_NET any -> [209.141.52.25] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/209.141.52.25/; sid:900509087; rev:1;) alert tcp $HOME_NET any -> [51.68.146.200] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.68.146.200/; sid:900509093; rev:1;) alert tcp $HOME_NET any -> [168.119.40.176] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/168.119.40.176/; sid:900509095; rev:1;) alert tcp $HOME_NET any -> [51.83.254.164] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.83.254.164/; sid:900509096; rev:1;) alert tcp $HOME_NET any -> [121.7.223.45] 2222 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/121.7.223.45/; sid:900509099; rev:1;) alert tcp $HOME_NET any -> [104.244.79.94] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/104.244.79.94/; sid:900509134; rev:1;) alert tcp $HOME_NET any -> [157.245.111.0] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/157.245.111.0/; sid:900509135; rev:1;) alert tcp $HOME_NET any -> [103.224.241.74] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/103.224.241.74/; sid:900509136; rev:1;) alert tcp $HOME_NET any -> [51.83.251.245] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.83.251.245/; sid:900509137; rev:1;) alert tcp $HOME_NET any -> [51.68.147.233] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.68.147.233/; sid:900509153; rev:1;) alert tcp $HOME_NET any -> [51.83.250.240] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.83.250.240/; sid:900509155; rev:1;) alert tcp $HOME_NET any -> [162.243.103.246] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/162.243.103.246/; sid:900509159; rev:1;) alert tcp $HOME_NET any -> [207.154.208.93] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/207.154.208.93/; sid:900509164; rev:1;) alert tcp $HOME_NET any -> [134.209.164.181] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/134.209.164.181/; sid:900509165; rev:1;) alert tcp $HOME_NET any -> [58.96.74.42] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/58.96.74.42/; sid:900509167; rev:1;) alert tcp $HOME_NET any -> [51.68.144.94] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.68.144.94/; sid:900509170; rev:1;) alert tcp $HOME_NET any -> [165.227.153.100] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/165.227.153.100/; sid:900509177; rev:1;) alert tcp $HOME_NET any -> [190.107.19.180] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/190.107.19.180/; sid:900509178; rev:1;) alert tcp $HOME_NET any -> [54.37.130.166] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/54.37.130.166/; sid:900509185; rev:1;) alert tcp $HOME_NET any -> [104.236.40.81] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/104.236.40.81/; sid:900509204; rev:1;) alert tcp $HOME_NET any -> [138.197.68.35] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/138.197.68.35/; sid:900509205; rev:1;) alert tcp $HOME_NET any -> [94.36.193.176] 2222 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/94.36.193.176/; sid:900509212; rev:1;) alert tcp $HOME_NET any -> [54.37.131.107] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/54.37.131.107/; sid:900509213; rev:1;) alert tcp $HOME_NET any -> [54.37.130.77] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/54.37.130.77/; sid:900509214; rev:1;) alert tcp $HOME_NET any -> [178.128.31.80] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/178.128.31.80/; sid:900509225; rev:1;) alert tcp $HOME_NET any -> [51.161.73.194] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.161.73.194/; sid:900509226; rev:1;) alert tcp $HOME_NET any -> [157.245.196.132] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/157.245.196.132/; sid:900509227; rev:1;) alert tcp $HOME_NET any -> [198.199.70.22] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/198.199.70.22/; sid:900509229; rev:1;) alert tcp $HOME_NET any -> [165.22.254.68] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/165.22.254.68/; sid:900509230; rev:1;) alert tcp $HOME_NET any -> [185.62.57.27] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/185.62.57.27/; sid:900509261; rev:1;) alert tcp $HOME_NET any -> [51.68.145.54] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.68.145.54/; sid:900509262; rev:1;) alert tcp $HOME_NET any -> [144.91.78.55] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/144.91.78.55/; sid:900509270; rev:1;) alert tcp $HOME_NET any -> [172.105.226.75] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/172.105.226.75/; sid:900509271; rev:1;) alert tcp $HOME_NET any -> [37.187.114.15] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/37.187.114.15/; sid:900509273; rev:1;) alert tcp $HOME_NET any -> [190.107.19.179] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/190.107.19.179/; sid:900509274; rev:1;) alert tcp $HOME_NET any -> [185.62.57.182] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/185.62.57.182/; sid:900509277; rev:1;) alert tcp $HOME_NET any -> [69.63.64.48] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/69.63.64.48/; sid:900509286; rev:1;) alert tcp $HOME_NET any -> [201.73.143.120] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/201.73.143.120/; sid:900509287; rev:1;) alert tcp $HOME_NET any -> [145.239.28.110] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/145.239.28.110/; sid:900509295; rev:1;) alert tcp $HOME_NET any -> [139.162.113.169] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/139.162.113.169/; sid:900509303; rev:1;) alert tcp $HOME_NET any -> [185.62.58.209] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/185.62.58.209/; sid:900509305; rev:1;) alert tcp $HOME_NET any -> [51.210.158.156] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.210.158.156/; sid:900509316; rev:1;) alert tcp $HOME_NET any -> [145.239.30.73] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/145.239.30.73/; sid:900509321; rev:1;) alert tcp $HOME_NET any -> [213.232.235.90] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/213.232.235.90/; sid:900509324; rev:1;) alert tcp $HOME_NET any -> [37.221.67.104] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/37.221.67.104/; sid:900509325; rev:1;) alert tcp $HOME_NET any -> [185.62.56.181] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/185.62.56.181/; sid:900509327; rev:1;) alert tcp $HOME_NET any -> [100.38.242.113] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/100.38.242.113/; sid:900509342; rev:1;) alert tcp $HOME_NET any -> [185.62.57.25] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/185.62.57.25/; sid:900509349; rev:1;) alert tcp $HOME_NET any -> [94.103.188.112] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/94.103.188.112/; sid:900509350; rev:1;) alert tcp $HOME_NET any -> [51.83.254.3] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.83.254.3/; sid:900509353; rev:1;) alert tcp $HOME_NET any -> [81.193.30.90] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/81.193.30.90/; sid:900509356; rev:1;) alert tcp $HOME_NET any -> [37.221.67.122] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/37.221.67.122/; sid:900509364; rev:1;) alert tcp $HOME_NET any -> [51.83.255.232] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.83.255.232/; sid:900509369; rev:1;) alert tcp $HOME_NET any -> [185.62.58.60] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/185.62.58.60/; sid:900509371; rev:1;) alert tcp $HOME_NET any -> [185.62.56.129] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/185.62.56.129/; sid:900509375; rev:1;) alert tcp $HOME_NET any -> [152.89.247.79] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/152.89.247.79/; sid:900509376; rev:1;) alert tcp $HOME_NET any -> [47.156.129.52] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/47.156.129.52/; sid:900509385; rev:1;) alert tcp $HOME_NET any -> [54.38.136.111] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/54.38.136.111/; sid:900509386; rev:1;) alert tcp $HOME_NET any -> [51.83.253.131] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.83.253.131/; sid:900509389; rev:1;) alert tcp $HOME_NET any -> [104.168.201.219] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/104.168.201.219/; sid:900509390; rev:1;) alert tcp $HOME_NET any -> [185.62.58.155] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/185.62.58.155/; sid:900509400; rev:1;) alert tcp $HOME_NET any -> [209.141.58.141] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/209.141.58.141/; sid:900509401; rev:1;) alert tcp $HOME_NET any -> [145.239.135.155] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/145.239.135.155/; sid:900509403; rev:1;) alert tcp $HOME_NET any -> [54.37.131.14] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/54.37.131.14/; sid:900509410; rev:1;) alert tcp $HOME_NET any -> [185.62.58.175] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/185.62.58.175/; sid:900509414; rev:1;) alert tcp $HOME_NET any -> [209.141.49.203] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/209.141.49.203/; sid:900509423; rev:1;) alert tcp $HOME_NET any -> [185.62.57.166] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/185.62.57.166/; sid:900509432; rev:1;) alert tcp $HOME_NET any -> [54.38.136.209] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/54.38.136.209/; sid:900509436; rev:1;) alert tcp $HOME_NET any -> [54.38.138.94] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/54.38.138.94/; sid:900509439; rev:1;) alert tcp $HOME_NET any -> [209.141.46.50] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/209.141.46.50/; sid:900509440; rev:1;) alert tcp $HOME_NET any -> [209.141.51.187] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/209.141.51.187/; sid:900509445; rev:1;) alert tcp $HOME_NET any -> [217.165.157.202] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/217.165.157.202/; sid:900509447; rev:1;) alert tcp $HOME_NET any -> [37.186.58.99] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/37.186.58.99/; sid:900509448; rev:1;) alert tcp $HOME_NET any -> [213.239.212.5] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/213.239.212.5/; sid:900509449; rev:1;) alert tcp $HOME_NET any -> [188.165.79.151] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/188.165.79.151/; sid:900509450; rev:1;) alert tcp $HOME_NET any -> [45.55.191.130] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/45.55.191.130/; sid:900509454; rev:1;) alert tcp $HOME_NET any -> [174.138.33.49] 7080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/174.138.33.49/; sid:900509455; rev:1;) alert tcp $HOME_NET any -> [5.253.30.17] 7080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/5.253.30.17/; sid:900509456; rev:1;) alert tcp $HOME_NET any -> [104.248.155.133] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/104.248.155.133/; sid:900509459; rev:1;) alert tcp $HOME_NET any -> [131.100.24.199] 4143 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/131.100.24.199/; sid:900509460; rev:1;) alert tcp $HOME_NET any -> [128.199.93.156] 7080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/128.199.93.156/; sid:900509461; rev:1;) alert tcp $HOME_NET any -> [96.125.171.165] 7080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/96.125.171.165/; sid:900509463; rev:1;) alert tcp $HOME_NET any -> [103.159.224.46] 7080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/103.159.224.46/; sid:900509465; rev:1;) alert tcp $HOME_NET any -> [178.128.23.9] 8081 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/178.128.23.9/; sid:900509467; rev:1;) alert tcp $HOME_NET any -> [178.128.31.80] 80 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/178.128.31.80/; sid:900509471; rev:1;) alert tcp $HOME_NET any -> [178.128.82.218] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/178.128.82.218/; sid:900509472; rev:1;) alert tcp $HOME_NET any -> [128.199.225.17] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/128.199.225.17/; sid:900509473; rev:1;) alert tcp $HOME_NET any -> [146.59.151.250] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/146.59.151.250/; sid:900509475; rev:1;) alert tcp $HOME_NET any -> [142.11.212.144] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/142.11.212.144/; sid:900509476; rev:1;) alert tcp $HOME_NET any -> [185.62.58.207] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/185.62.58.207/; sid:900509478; rev:1;) alert tcp $HOME_NET any -> [185.62.56.137] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/185.62.56.137/; sid:900509484; rev:1;) alert tcp $HOME_NET any -> [198.98.55.160] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/198.98.55.160/; sid:900509485; rev:1;) alert tcp $HOME_NET any -> [144.91.92.120] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/144.91.92.120/; sid:900509488; rev:1;) alert tcp $HOME_NET any -> [185.62.57.202] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/185.62.57.202/; sid:900509492; rev:1;) alert tcp $HOME_NET any -> [205.185.122.143] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/205.185.122.143/; sid:900509493; rev:1;) alert tcp $HOME_NET any -> [209.141.41.46] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/209.141.41.46/; sid:900509494; rev:1;) alert tcp $HOME_NET any -> [104.168.144.212] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/104.168.144.212/; sid:900509497; rev:1;) alert tcp $HOME_NET any -> [203.217.140.239] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/203.217.140.239/; sid:900509498; rev:1;) alert tcp $HOME_NET any -> [34.80.191.247] 7080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/34.80.191.247/; sid:900509499; rev:1;) alert tcp $HOME_NET any -> [138.197.64.211] 7080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/138.197.64.211/; sid:900509501; rev:1;) alert tcp $HOME_NET any -> [1.234.21.73] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/1.234.21.73/; sid:900509502; rev:1;) alert tcp $HOME_NET any -> [51.68.146.186] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.68.146.186/; sid:900509505; rev:1;) alert tcp $HOME_NET any -> [54.37.70.105] 443 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/54.37.70.105/; sid:900509506; rev:1;) alert tcp $HOME_NET any -> [178.128.31.80] 7080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/178.128.31.80/; sid:900509508; rev:1;) alert tcp $HOME_NET any -> [165.22.211.113] 8081 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/165.22.211.113/; sid:900509509; rev:1;) alert tcp $HOME_NET any -> [45.55.44.204] 7080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/45.55.44.204/; sid:900509510; rev:1;) alert tcp $HOME_NET any -> [106.51.48.188] 50001 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/106.51.48.188/; sid:900509511; rev:1;) alert tcp $HOME_NET any -> [205.185.123.137] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/205.185.123.137/; sid:900509514; rev:1;) alert tcp $HOME_NET any -> [209.141.49.72] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/209.141.49.72/; sid:900509516; rev:1;) alert tcp $HOME_NET any -> [185.62.57.94] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/185.62.57.94/; sid:900509519; rev:1;) alert tcp $HOME_NET any -> [51.68.144.13] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.68.144.13/; sid:900509521; rev:1;) alert tcp $HOME_NET any -> [24.158.23.166] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/24.158.23.166/; sid:900509523; rev:1;) alert tcp $HOME_NET any -> [70.51.137.244] 2222 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/70.51.137.244/; sid:900509525; rev:1;) alert tcp $HOME_NET any -> [54.37.136.187] 8080 (msg:"Feodo Tracker: potential Emotet CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/54.37.136.187/; sid:900509526; rev:1;) alert tcp $HOME_NET any -> [45.11.19.70] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/45.11.19.70/; sid:900509527; rev:1;) alert tcp $HOME_NET any -> [146.19.173.120] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/146.19.173.120/; sid:900509529; rev:1;) alert tcp $HOME_NET any -> [146.19.173.33] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/146.19.173.33/; sid:900509530; rev:1;) alert tcp $HOME_NET any -> [45.61.184.227] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/45.61.184.227/; sid:900509531; rev:1;) alert tcp $HOME_NET any -> [51.68.145.174] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/51.68.145.174/; sid:900509533; rev:1;) alert tcp $HOME_NET any -> [209.141.57.151] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/209.141.57.151/; sid:900509534; rev:1;) alert tcp $HOME_NET any -> [209.141.35.21] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/209.141.35.21/; sid:900509535; rev:1;) alert tcp $HOME_NET any -> [92.132.132.81] 2222 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/92.132.132.81/; sid:900509536; rev:1;) alert tcp $HOME_NET any -> [176.45.218.138] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/176.45.218.138/; sid:900509538; rev:1;) alert tcp $HOME_NET any -> [174.80.15.101] 2083 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/174.80.15.101/; sid:900509539; rev:1;) alert tcp $HOME_NET any -> [86.97.10.37] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/86.97.10.37/; sid:900509545; rev:1;) alert tcp $HOME_NET any -> [81.158.239.251] 2078 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/81.158.239.251/; sid:900509547; rev:1;) alert tcp $HOME_NET any -> [179.111.8.52] 32101 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/179.111.8.52/; sid:900509548; rev:1;) alert tcp $HOME_NET any -> [187.116.126.216] 32101 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/187.116.126.216/; sid:900509549; rev:1;) alert tcp $HOME_NET any -> [24.54.48.11] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/24.54.48.11/; sid:900509550; rev:1;) alert tcp $HOME_NET any -> [86.98.78.118] 993 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/86.98.78.118/; sid:900509551; rev:1;) alert tcp $HOME_NET any -> [1.161.118.53] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/1.161.118.53/; sid:900509552; rev:1;) alert tcp $HOME_NET any -> [39.44.116.107] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/39.44.116.107/; sid:900509555; rev:1;) alert tcp $HOME_NET any -> [85.6.232.221] 2222 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/85.6.232.221/; sid:900509556; rev:1;) alert tcp $HOME_NET any -> [39.57.56.11] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/39.57.56.11/; sid:900509557; rev:1;) alert tcp $HOME_NET any -> [1.161.118.53] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/1.161.118.53/; sid:900509558; rev:1;) alert tcp $HOME_NET any -> [39.52.44.132] 995 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/39.52.44.132/; sid:900509559; rev:1;) alert tcp $HOME_NET any -> [197.92.136.122] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/197.92.136.122/; sid:900509561; rev:1;) alert tcp $HOME_NET any -> [88.240.59.52] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/88.240.59.52/; sid:900509562; rev:1;) alert tcp $HOME_NET any -> [86.213.75.30] 2078 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/86.213.75.30/; sid:900509563; rev:1;) alert tcp $HOME_NET any -> [98.50.153.207] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/98.50.153.207/; sid:900509565; rev:1;) alert tcp $HOME_NET any -> [198.98.59.39] 443 (msg:"Feodo Tracker: potential BumbleBee CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/198.98.59.39/; sid:900509566; rev:1;) # END 321 entries