################################################################ # abuse.ch Feodo Tracker Suricata / Snort Ruleset # # Last updated: 2024-03-26 23:30:15 UTC # # # # Terms Of Use: https://feodotracker.abuse.ch/blocklist/ # # For questions please contact feodotracker [at] abuse.ch # ################################################################ # alert tcp $HOME_NET any -> [192.9.135.73] 1194 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/192.9.135.73/; sid:900512344; rev:1;) alert tcp $HOME_NET any -> [85.239.243.155] 5000 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/85.239.243.155/; sid:900513593; rev:1;) alert tcp $HOME_NET any -> [37.60.242.85] 9785 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/37.60.242.85/; sid:900513596; rev:1;) alert tcp $HOME_NET any -> [178.18.246.136] 2078 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/178.18.246.136/; sid:900513601; rev:1;) alert tcp $HOME_NET any -> [23.226.138.143] 2083 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/23.226.138.143/; sid:900513602; rev:1;) alert tcp $HOME_NET any -> [23.226.138.161] 5242 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/23.226.138.161/; sid:900513603; rev:1;) alert tcp $HOME_NET any -> [86.38.225.106] 2221 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/86.38.225.106/; sid:900513606; rev:1;) alert tcp $HOME_NET any -> [104.129.55.106] 13783 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/104.129.55.106/; sid:900513608; rev:1;) alert tcp $HOME_NET any -> [103.82.243.5] 13785 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/103.82.243.5/; sid:900513611; rev:1;) alert tcp $HOME_NET any -> [104.129.55.105] 2223 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/104.129.55.105/; sid:900513612; rev:1;) alert tcp $HOME_NET any -> [89.117.23.185] 2221 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/89.117.23.185/; sid:900513629; rev:1;) alert tcp $HOME_NET any -> [154.12.248.41] 5000 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/154.12.248.41/; sid:900513632; rev:1;) alert tcp $HOME_NET any -> [89.117.23.186] 5632 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/89.117.23.186/; sid:900513634; rev:1;) alert tcp $HOME_NET any -> [154.12.233.66] 2224 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/154.12.233.66/; sid:900513637; rev:1;) alert tcp $HOME_NET any -> [192.248.159.76] 2222 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/192.248.159.76/; sid:900513639; rev:1;) alert tcp $HOME_NET any -> [65.20.73.169] 13783 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/65.20.73.169/; sid:900513640; rev:1;) alert tcp $HOME_NET any -> [84.46.240.42] 2083 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/84.46.240.42/; sid:900513641; rev:1;) alert tcp $HOME_NET any -> [209.126.86.48] 1194 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/209.126.86.48/; sid:900513642; rev:1;) alert tcp $HOME_NET any -> [154.12.236.248] 13786 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/154.12.236.248/; sid:900513643; rev:1;) alert tcp $HOME_NET any -> [94.72.104.77] 13724 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/94.72.104.77/; sid:900513644; rev:1;) alert tcp $HOME_NET any -> [154.53.55.165] 13783 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/154.53.55.165/; sid:900513645; rev:1;) alert tcp $HOME_NET any -> [94.72.104.80] 5000 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/94.72.104.80/; sid:900513646; rev:1;) alert tcp $HOME_NET any -> [198.38.94.213] 2224 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/198.38.94.213/; sid:900513647; rev:1;) alert tcp $HOME_NET any -> [158.220.95.214] 5243 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/158.220.95.214/; sid:900513648; rev:1;) alert tcp $HOME_NET any -> [64.23.199.206] 1194 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/64.23.199.206/; sid:900513649; rev:1;) alert tcp $HOME_NET any -> [172.232.208.90] 2223 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/172.232.208.90/; sid:900513650; rev:1;) alert tcp $HOME_NET any -> [213.199.41.33] 13721 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/213.199.41.33/; sid:900513651; rev:1;) alert tcp $HOME_NET any -> [194.233.91.144] 5000 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/194.233.91.144/; sid:900513652; rev:1;) alert tcp $HOME_NET any -> [158.220.95.215] 5242 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/158.220.95.215/; sid:900513653; rev:1;) alert tcp $HOME_NET any -> [84.247.157.112] 13783 (msg:"Feodo Tracker: potential Pikabot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/84.247.157.112/; sid:900513654; rev:1;) # END 30 entries