################################################################ # abuse.ch Feodo Tracker Suricata / Snort Ruleset # # Last updated: 2024-11-26 19:35:48 UTC # # # # Terms Of Use: https://feodotracker.abuse.ch/blocklist/ # # For questions please contact feodotracker [at] abuse.ch # ################################################################ # alert tcp $HOME_NET any -> [3.228.226.42] 443 (msg:"Feodo Tracker: potential QakBot CnC Traffic detected"; threshold: type limit, track by_src, seconds 60, count 1; classtype:trojan-activity; reference:url, feodotracker.abuse.ch/browse/host/3.228.226.42/; sid:900513673; rev:1;) # END 1 entries